Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-65524 |
|
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
|
| CVE-2026-65486 |
|
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
|
| CVE-2026-65499 |
|
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
|
| CVE-2026-65487 |
|
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
|
| CVE-2026-65485 |
|
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
|
| CVE-2026-65491 |
|
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
|
| CVE-2026-65489 |
|
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
|
| CVE-2026-65525 |
|
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
|
| CVE-2026-65500 |
|
Vulnerability in wordpress (CVE-2026-65500)
vulnerability in wordpress (CVE-2026-65500). Confidential information can be exposed externally.
|
| CVE-2026-65479 |
|
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
|
| CVE-2026-65476 |
|
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
|
| CVE-2026-65469 |
|
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
|
| CVE-2026-65472 |
|
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
|
| CVE-2026-65484 |
|
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
|
| CVE-2026-65478 |
|
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
|
| CVE-2026-65468 |
|
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
|
| CVE-2026-65457 |
|
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
|
| CVE-2026-65452 |
|
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
|
| CVE-2026-65453 |
|
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
|
| CVE-2026-61973 |
|
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
|
| CVE-2026-61943 |
|
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
|
| CVE-2026-64814 |
|
Vulnerability in jetbrains (CVE-2026-64814)
vulnerability in jetbrains (CVE-2026-64814). Confidential information can be exposed externally.
|
| CVE-2026-59547 |
|
Vulnerability in CVE-2026-59547 (CVE-2026-59547)
vulnerability in CVE-2026-59547 (CVE-2026-59547). Data can be tampered with by attackers.
|
| CVE-2026-61954 |
|
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
|
| CVE-2026-61972 |
|
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
|
| CVE-2026-57703 |
|
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.
|
| CVE-2026-57717 |
|
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.
|
| CVE-2026-59522 |
|
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
|
| CVE-2026-57808 |
|
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
|
| CVE-2026-57425 |
|
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.
|
| CVE-2026-25424 |
|
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.
|
| CVE-2026-27399 |
|
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.
|
| CVE-2026-25427 |
|
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
Subscriber Broken Access Control in eRoom <= 1.7.1 versions.
|
| CVE-2026-27422 |
|
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.
|
| CVE-2026-27423 |
|
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.
|
| CVE-2026-25466 |
|
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
|
| CVE-2026-27418 |
|
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.
|
| CVE-2026-27391 |
|
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
|
| CVE-2026-27377 |
|
Vulnerability in wordpress (CVE-2026-27377)
vulnerability in wordpress (CVE-2026-27377). Confidential information can be exposed externally.
|
| CVE-2026-27355 |
|
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.
|
| CVE-2026-27392 |
|
Contributor Broken Access Control in uListing <= 2.2.0 versions.
Contributor Broken Access Control in uListing <= 2.2.0 versions.
|
| CVE-2026-57367 |
|
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
|
| CVE-2026-15827 |
|
Vulnerability in wordpress (CVE-2026-15827)
vulnerability in wordpress (CVE-2026-15827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15015 |
|
Vulnerability in wordpress (CVE-2026-15015)
vulnerability in wordpress (CVE-2026-15015). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59677 |
|
Vulnerability in CVE-2026-59677 (CVE-2026-59677)
vulnerability in CVE-2026-59677 (CVE-2026-59677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12082 |
|
Vulnerability in wordpress (CVE-2026-12082)
vulnerability in wordpress (CVE-2026-12082). Confidential information can be exposed externally.
|
| CVE-2026-13078 |
|
Vulnerability in mongodb (CVE-2026-13078)
vulnerability in mongodb (CVE-2026-13078). Confidential information can be exposed externally.
|
| CVE-2026-65011 |
|
Vulnerability in CVE-2026-65011 (CVE-2026-65011)
vulnerability in CVE-2026-65011 (CVE-2026-65011). Risk of unauthorized operations or information disclosure. Exploitable via `POST /events/definitions/{definitionId}/duplicate`.
|
| CVE-2026-7328 |
|
Vulnerability in dos (CVE-2026-7328)
vulnerability in dos (CVE-2026-7328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16544 |
|
Vulnerability in CVE-2026-16544 (CVE-2026-16544)
vulnerability in CVE-2026-16544 (CVE-2026-16544). Confidential information can be exposed externally.
|