Export limit exceeded: 404393 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404393 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404393 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404393 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96334 | 2026-10-11 | 5.6 Medium | ||
| Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 5.2.7. | ||||
| CVE-2026-96278 | 2026-10-11 | 7.2 High | ||
| The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them. | ||||
| CVE-2026-95684 | 2026-10-11 | 7.2 High | ||
| The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-95597 | 2026-10-11 | 6.5 Medium | ||
| Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17. | ||||
| CVE-2026-94676 | 2026-10-11 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0. | ||||
| CVE-2026-94666 | 2026-10-11 | 7.5 High | ||
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1. | ||||
| CVE-2026-94590 | 2026-10-11 | 6.5 Medium | ||
| Improper Verification of Source of a Communication Channel vulnerability in CodePeople2 Sell Downloads sell-downloads allows Exploitation of Trusted Credentials.This issue affects Sell Downloads: from n/a through 1.2.3. | ||||
| CVE-2026-94421 | 2026-10-11 | 6.4 Medium | ||
| The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-94065 | 2026-10-11 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3. | ||||
| CVE-2026-94064 | 2026-10-11 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5. | ||||
| CVE-2026-93950 | 2026-10-11 | 7.5 High | ||
| Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108. | ||||
| CVE-2026-93949 | 2026-10-11 | 7.1 High | ||
| Authentication Bypass Using an Alternate Path or Channel vulnerability in Omegathemes Grocery Shopping Store grocery-shopping-store allows Password Recovery Exploitation.This issue affects Grocery Shopping Store: from n/a through 1.3.3. | ||||
| CVE-2026-93945 | 2 Axiomthemes, Wordpress-extensions | 2 Balance, Balance | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0. | ||||
| CVE-2026-93944 | 2 Themerex Group, Wordpress-extensions | 2 Camelia, Camelia | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15. | ||||
| CVE-2026-93943 | 2 Themerex Group, Wordpress-extensions | 2 Convex, Convex | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0. | ||||
| CVE-2026-93942 | 2 Themerex Group, Wordpress-extensions | 2 Dwell, Dwell | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0. | ||||
| CVE-2026-93941 | 2 Themerex Group, Wordpress-extensions | 2 Edema, Edema | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2. | ||||
| CVE-2026-93940 | 2 Themerex Group, Wordpress-extensions | 2 Greeny, Greeny | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0. | ||||
| CVE-2026-93938 | 2 Themerex Group, Wordpress-extensions | 2 Hogwords, Hogwords | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7. | ||||
| CVE-2026-93937 | 2 Themerex Group, Wordpress-extensions | 2 Hygia, Hygia | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0. | ||||