Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75912 |
|
Vulnerability in CVE-2026-75912 (CVE-2026-75912)
vulnerability in CVE-2026-75912 (CVE-2026-75912). Confidential information can be exposed externally.
|
| CVE-2026-75911 |
|
Code Injection in CVE-2026-75911 (CVE-2026-75911)
code injection in CVE-2026-75911 (CVE-2026-75911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75859 |
|
Path Traversal in CVE-2026-75859 (CVE-2026-75859)
path traversal in CVE-2026-75859 (CVE-2026-75859). Confidential information can be exposed externally.
|
| CVE-2026-75858 |
|
Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-75857 |
|
Privilege Escalation in CVE-2026-75857 (CVE-2026-75857)
vulnerability in CVE-2026-75857 (CVE-2026-75857). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-75856 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75856)
SSRF in ssrf (CVE-2026-75856). Confidential information can be exposed externally.
|
| CVE-2026-71365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71365)
SSRF in ssrf (CVE-2026-71365). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-49227 |
|
Vulnerability in CVE-2026-49227 (CVE-2026-49227)
vulnerability in CVE-2026-49227 (CVE-2026-49227). Data can be tampered with by attackers.
|
| CVE-2026-49226 |
|
Vulnerability in CVE-2026-49226 (CVE-2026-49226)
vulnerability in CVE-2026-49226 (CVE-2026-49226). Data can be tampered with by attackers.
|
| CVE-2026-49221 |
|
Vulnerability in CVE-2026-49221 (CVE-2026-49221)
vulnerability in CVE-2026-49221 (CVE-2026-49221). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45116 |
|
Cross-Site Scripting (XSS) in CVE-2026-45116 (CVE-2026-45116)
cross-site scripting in CVE-2026-45116 (CVE-2026-45116). Confidential information can be exposed externally.
|
| CVE-2026-45115 |
|
Cross-Site Scripting (XSS) in CVE-2026-45115 (CVE-2026-45115)
cross-site scripting in CVE-2026-45115 (CVE-2026-45115). Confidential information can be exposed externally.
|
| CVE-2026-19501 |
|
Vulnerability in CVE-2026-19501 (CVE-2026-19501)
vulnerability in CVE-2026-19501 (CVE-2026-19501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19500 |
|
Vulnerability in CVE-2026-19500 (CVE-2026-19500)
vulnerability in CVE-2026-19500 (CVE-2026-19500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75898 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-75898 (CVE-2026-75898)
SSRF in CVE-2026-75898 (CVE-2026-75898). Confidential information can be exposed externally.
|
| CVE-2026-74012 |
|
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
|
| CVE-2026-73994 |
|
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
|
| CVE-2026-73396 |
|
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
|
| CVE-2026-73997 |
|
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
|
| CVE-2026-73400 |
|
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
|
| CVE-2026-73393 |
|
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
|
| CVE-2026-73382 |
|
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
|
| CVE-2026-73378 |
|
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
|
| CVE-2026-73377 |
|
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
|
| CVE-2026-73362 |
|
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
|
| CVE-2026-73375 |
|
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
|
| CVE-2026-73360 |
|
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
|
| CVE-2026-73351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-73351)
cross-site scripting in wordpress (CVE-2026-73351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73356 |
|
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
|
| CVE-2026-73367 |
|
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
|
| CVE-2026-73361 |
|
Cross-Site Scripting (XSS) in CVE-2026-73361 (CVE-2026-73361)
cross-site scripting in CVE-2026-73361 (CVE-2026-73361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73345 |
|
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
|
| CVE-2026-73338 |
|
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
|
| CVE-2026-73358 |
|
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
|
| CVE-2026-73350 |
|
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
|
| CVE-2026-73342 |
|
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
|
| CVE-2026-73190 |
|
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
|
| CVE-2026-73181 |
|
Path Traversal in CVE-2026-73181 (CVE-2026-73181)
path traversal in CVE-2026-73181 (CVE-2026-73181). Confidential information can be exposed externally.
|
| CVE-2026-68567 |
|
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
|
| CVE-2026-66635 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
|
| CVE-2026-66046 |
|
Vulnerability in c (CVE-2026-66046)
vulnerability in c (CVE-2026-66046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66793 |
|
Vulnerability in privilege-escalation (CVE-2026-66793)
vulnerability in privilege-escalation (CVE-2026-66793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66622 |
|
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
|
| CVE-2026-66629 |
|
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
|
| CVE-2026-66621 |
|
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
|
| CVE-2026-66633 |
|
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
|
| CVE-2026-66667 |
|
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
|
| CVE-2026-32473 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32473)
SSRF in ssrf (CVE-2026-32473). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32547 |
|
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
|
| CVE-2026-66620 |
|
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
|