|
CVE-2026-8176
|
|
wordpress に 権限昇格 (CVE-2026-8176)
wordpress に 脆弱性 (CVE-2026-8176) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
WordPress
権限昇格
Cwe 269
|
2ヶ月前
|
|
CVE-2026-5416
|
|
CVE-2026-5416 に OSコマンドインジェクション (CVE-2026-5416)
CVE-2026-5416 に OSコマンドインジェクション (CVE-2026-5416) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
CWE-78: OSコマンドインジェクション
|
2ヶ月前
|
|
CVE-2026-54198
|
|
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-54191
|
|
Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-52712
|
|
Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-52711
|
|
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39581
|
|
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-39490
|
|
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39437
|
|
CVE-2026-39437 に クロスサイトスクリプティング (CVE-2026-39437)
CVE-2026-39437 に XSS (クロスサイトスクリプティング) (CVE-2026-39437) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2025-68045
|
|
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-46331
|
|
linux の脆弱性 (CVE-2026-46331)
linux に 脆弱性 (CVE-2026-46331) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
Cwe 190
CWE-787: 境界外書き込み
Linux
Linux Kernel
|
2ヶ月前
|
|
CVE-2026-8444
|
|
wordpress に SQLインジェクション (CVE-2026-8444)
wordpress に SQLインジェクション (CVE-2026-8444) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
WordPress
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-6933
|
|
wordpress に 危険なファイルアップロード (CVE-2026-6933)
wordpress に 脆弱性 (CVE-2026-6933) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
PHP
WordPress
リモートコード実行 (RCE)
Cwe 434
|
2ヶ月前
|
|
CVE-2026-8443
|
|
wordpress に SQLインジェクション (CVE-2026-8443)
wordpress に SQLインジェクション (CVE-2026-8443) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
WordPress
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-7273
|
|
CVE-2026-7273 の脆弱性 (CVE-2026-7273)
CVE-2026-7273 に 脆弱性 (CVE-2026-7273) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
Cwe 121
|
2ヶ月前
|
|
CVE-2026-12161
|
|
devolutions に OSコマンドインジェクション (CVE-2026-12161)
devolutions に OSコマンドインジェクション (CVE-2026-12161) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
CWE-78: OSコマンドインジェクション
Devolutions
Remote Desktop Manager
|
2ヶ月前
|
|
CVE-2026-48723
|
|
CVE-2026-48723 に OSコマンドインジェクション (CVE-2026-48723)
CVE-2026-48723 に OSコマンドインジェクション (CVE-2026-48723) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
JavaScript
CWE-78: OSコマンドインジェクション
|
2ヶ月前
|
|
CVE-2026-52700
|
|
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-52694
|
|
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
|
High
|
Cwe 497
|
2ヶ月前
|
|
CVE-2026-52699
|
|
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
|
High
|
Cwe 639
|
2ヶ月前
|
|
CVE-2026-52697
|
|
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-52702
|
|
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-49780
|
|
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
Customer Privilege Escalation in Dokan <= 5.0.2 versions.
|
High
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-52692
|
|
Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
|
High
|
Cwe 201
|
2ヶ月前
|
|
CVE-2026-52695
|
|
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
|
High
|
Cwe 201
|
2ヶ月前
|
|
CVE-2026-49065
|
|
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-49061
|
|
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
|
High
|
CWE-22: パストラバーサル
|
2ヶ月前
|
|
CVE-2026-49063
|
|
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
|
High
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-49056
|
|
CVE-2026-49056 の脆弱性 (CVE-2026-49056)
CVE-2026-49056 に 脆弱性 (CVE-2026-49056) が存在。機密情報が外部に流出する可能性があります。
|
High
|
Cwe 497
|
2ヶ月前
|
|
CVE-2026-48970
|
|
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
|
High
|
Cwe 288
|
2ヶ月前
|
|
CVE-2026-49066
|
|
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
|
High
|
Cwe 497
|
2ヶ月前
|
|
CVE-2026-49078
|
|
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
|
High
|
Cwe 1284
|
2ヶ月前
|
|
CVE-2026-48964
|
|
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
|
High
|
WordPress
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-48889
|
|
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
|
High
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-48966
|
|
Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-49083
|
|
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
|
High
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-49070
|
|
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-49082
|
|
CVE-2026-49082 の脆弱性 (CVE-2026-49082)
CVE-2026-49082 に 脆弱性 (CVE-2026-49082) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
Cwe 201
|
2ヶ月前
|
|
CVE-2026-49055
|
|
CVE-2026-49055 に クロスサイトスクリプティング (CVE-2026-49055)
CVE-2026-49055 に XSS (クロスサイトスクリプティング) (CVE-2026-49055) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-49068
|
|
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
|
High
|
Cwe 497
|
2ヶ月前
|
|
CVE-2026-49110
|
|
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
|
High
|
Cwe 1284
|
2ヶ月前
|
|
CVE-2026-49112
|
|
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
|
High
|
パストラバーサル
Cwe 35
|
2ヶ月前
|
|
CVE-2026-48838
|
|
Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-48876
|
|
Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-48882
|
|
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-48868
|
|
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
|
High
|
Cwe 639
|
2ヶ月前
|
|
CVE-2026-48867
|
|
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-48835
|
|
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-48872
|
|
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
|
High
|
Cwe 639
|
2ヶ月前
|
|
CVE-2026-48883
|
|
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
|
High
|
Cwe 862
|
2ヶ月前
|