Export limit exceeded: 50164 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (50164 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-39780 | 2 Wordpress-extensions, Youzify | 2 Youzify, Youzify | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-39781 | 2 Dan Rossiter, Wordpress-extensions | 2 Document Gallery, Document Gallery | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Document Gallery <= 5.1.1 versions. | ||||
| CVE-2026-39784 | 2 Nicdark, Wordpress-extensions | 2 Hotel Booking, Hotel Booking | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions. | ||||
| CVE-2026-39788 | 2 Shamimsplugins, Wordpress-extensions | 2 Front End Pm, Front End Pm | 2026-10-06 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions. | ||||
| CVE-2026-39790 | 2 E4jvikwp, Wordpress-extensions | 2 Vikrentcar, Vikrentcar | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions. | ||||
| CVE-2026-40806 | 2 Plugin-devs, Wordpress-extensions | 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions. | ||||
| CVE-2026-40807 | 2 Aman, Wordpress-extensions | 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.6 versions. | ||||
| CVE-2026-102161 | 2026-10-06 | 8.8 High | ||
| An unauthenticated attacker located on an adjacent private network (or any attacker routed through a reverse proxy/load balancer that forwards client headers) can forge their source IP address and gain administrative session privileges on the CV-CUE backend. | ||||
| CVE-2026-101157 | 2026-10-06 | 8.7 High | ||
| A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services. | ||||
| CVE-2026-101156 | 2026-10-06 | 8.4 High | ||
| A stored cross-site scripting (XSS) vulnerability may allow an authenticated, high-privilege administrator to store malicious content in a configuration. The content may execute in another authenticated user's browser when that user views or compares the affected configuration. Successful exploitation may allow the attacker to act through the victim's authenticated browser session to access sensitive data, modify configurations, or disrupt managed wireless services. | ||||
| CVE-2026-105220 | 1 Klembot | 1 Twinejs | 2026-10-06 | 7.8 High |
| Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user. | ||||
| CVE-2026-104479 | 1 Mindstellar | 1 Osclass | 2026-10-06 | 5.4 Medium |
| Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute in the site origin for any visitor viewing the listing. | ||||
| CVE-2026-105188 | 1 Code-projects | 2 Human Resource Management, Human Resource Management System | 2026-10-06 | 3.5 Low |
| A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. | ||||
| CVE-2026-105397 | 2 Thimpress, Wordpress-extensions | 2 Learnpress, Learnpress | 2026-10-06 | 5.4 Medium |
| LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation fields. Attackers with the Instructor role can submit unsanitized payloads through the update_question AJAX handler that execute in the session of every student taking the quiz. | ||||
| CVE-2026-42634 | 2 Bplugins, Wordpress-extensions | 2 Video Background Block – Use Video As Background In The Section., Video Background Block Use Video As Background In The Section | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. | ||||
| CVE-2026-42635 | 2 Wordpress-extensions, Wpgenie | 2 Woocommerce Simple Auctions, Woocommerce Simple Auctions | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. | ||||
| CVE-2026-42636 | 2 Wordpress-extensions, Wp Legal Pages | 2 Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent, Wp Cookie Notice For Gdpr, Ccpa & Eprivacy Consent | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6 versions. | ||||
| CVE-2026-94675 | 2 Fluent Forms Free Vs Pro, Wordpress-extensions | 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack <= 6.2.13 versions. | ||||
| CVE-2026-104394 | 2 Syed Balkhi, Wordpress-extensions | 2 Charitable, Charitable | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions. | ||||
| CVE-2026-104395 | 2 Picu, Wordpress-extensions | 2 Picu, Picu | 2026-10-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions. | ||||