Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-39472 Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
CVE-2026-39478 Unsafe Deserialization in CVE-2026-39478 (CVE-2026-39478)
vulnerability in CVE-2026-39478 (CVE-2026-39478). Successful exploitation can lead to full system takeover.
CVE-2026-39471 Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
CVE-2026-39480 Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
CVE-2026-39481 Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
CVE-2026-39498 Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
CVE-2026-39514 Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
CVE-2026-39507 Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
CVE-2026-39503 Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
CVE-2026-39499 Unsafe Deserialization in CVE-2026-39499 (CVE-2026-39499)
vulnerability in CVE-2026-39499 (CVE-2026-39499). Successful exploitation can lead to full system takeover.
CVE-2026-39513 Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
CVE-2026-39524 Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
CVE-2025-68840 Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
CVE-2026-39435 Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
CVE-2025-68872 Cross-Site Scripting (XSS) in CVE-2025-68872 (CVE-2025-68872)
cross-site scripting in CVE-2025-68872 (CVE-2025-68872). Risk of unauthorized operations or information disclosure.
CVE-2026-27089 Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
CVE-2026-34898 Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
CVE-2026-34886 Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
CVE-2026-24637 Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
CVE-2026-27333 Unsafe Deserialization in deserialization (CVE-2026-27333)
vulnerability in deserialization (CVE-2026-27333). Successful exploitation can lead to full system takeover.
CVE-2025-68851 Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
CVE-2026-34902 Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
CVE-2026-23970 Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
CVE-2026-39434 Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
CVE-2026-25425 Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
CVE-2026-34891 Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
CVE-2026-27407 Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
CVE-2026-34900 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
CVE-2025-59133 Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
CVE-2026-48708 Vulnerability in github.com/OliveTin/OliveTin (CVE-2026-48708)
vulnerability in github.com/OliveTin/OliveTin (CVE-2026-48708). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260521225117-d74da9314005` or later.
CVE-2026-54283 Vulnerability in starlette (CVE-2026-54283)
vulnerability in starlette (CVE-2026-54283). Risk of unauthorized operations or information disclosure. Exploitable via ``max_fields``. Mitigation: upgrade to `1.3.1` or later.
CVE-2026-53539 Vulnerability in python-multipart (CVE-2026-53539)
vulnerability in python-multipart (CVE-2026-53539). Risk of unauthorized operations or information disclosure. Exploitable via ``QuerystringParser``. Mitigation: upgrade to `0.0.30` or later.
CVE-2026-49853 Information Disclosure in tornado (CVE-2026-49853)
vulnerability in tornado (CVE-2026-49853). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `6.5.6` or later.
CVE-2026-49855 Vulnerability in tornado (CVE-2026-49855)
vulnerability in tornado (CVE-2026-49855). Risk of unauthorized operations or information disclosure. Exploitable via ``HTTPServer``. Mitigation: upgrade to `6.5.6` or later.
CVE-2026-53705 Vulnerability in CVE-2026-53705 (CVE-2026-53705)
vulnerability in CVE-2026-53705 (CVE-2026-53705). Risk of unauthorized operations or information disclosure.
CVE-2026-53704 Out-of-Bounds Read in CVE-2026-53704 (CVE-2026-53704)
vulnerability in CVE-2026-53704 (CVE-2026-53704). Risk of unauthorized operations or information disclosure.
CVE-2026-53703 Out-of-Bounds Read in CVE-2026-53703 (CVE-2026-53703)
vulnerability in CVE-2026-53703 (CVE-2026-53703). Risk of unauthorized operations or information disclosure.
CVE-2026-52722 Vulnerability in CVE-2026-52722 (CVE-2026-52722)
vulnerability in CVE-2026-52722 (CVE-2026-52722). Risk of unauthorized operations or information disclosure.
CVE-2026-52720 Vulnerability in CVE-2026-52720 (CVE-2026-52720)
vulnerability in CVE-2026-52720 (CVE-2026-52720). Successful exploitation can lead to full system takeover.
CVE-2026-52719 Out-of-Bounds Read in CVE-2026-52719 (CVE-2026-52719)
vulnerability in CVE-2026-52719 (CVE-2026-52719). Risk of unauthorized operations or information disclosure.
CVE-2026-50891 Vulnerability in github.com/mickael-kerjean/filestash (CVE-2026-50891)
vulnerability in github.com/mickael-kerjean/filestash (CVE-2026-50891). Confidential information can be exposed externally.
CVE-2026-50889 Vulnerability in dos (CVE-2026-50889)
vulnerability in dos (CVE-2026-50889). Risk of unauthorized operations or information disclosure.
CVE-2026-50888 SSRF (Server-Side Request Forgery) in koillection/koillection (CVE-2026-50888)
SSRF in koillection/koillection (CVE-2026-50888). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.4` or later.
CVE-2026-50885 Vulnerability in CVE-2026-50885 (CVE-2026-50885)
vulnerability in CVE-2026-50885 (CVE-2026-50885). Confidential information can be exposed externally.
CVE-2026-50884 Vulnerability in github.com/statping-ng/statping-ng (CVE-2026-50884)
vulnerability in github.com/statping-ng/statping-ng (CVE-2026-50884). Successful exploitation can lead to full system takeover.
CVE-2026-50882 Vulnerability in dos (CVE-2026-50882)
vulnerability in dos (CVE-2026-50882). Risk of unauthorized operations or information disclosure.
CVE-2026-50881 Vulnerability in CVE-2026-50881 (CVE-2026-50881)
vulnerability in CVE-2026-50881 (CVE-2026-50881). Confidential information can be exposed externally.
CVE-2026-48818 SSRF (Server-Side Request Forgery) in starlette (CVE-2026-48818)
SSRF in starlette (CVE-2026-48818). Confidential information can be exposed externally. Exploitable via ``StaticFiles``. Mitigation: upgrade to `1.1.0` or later.
CVE-2026-50877 Path Traversal in path-traversal (CVE-2026-50877)
path traversal in path-traversal (CVE-2026-50877). Confidential information can be exposed externally.
CVE-2026-50875 Vulnerability in CVE-2026-50875 (CVE-2026-50875)
vulnerability in CVE-2026-50875 (CVE-2026-50875). Data can be tampered with by attackers.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →