Export limit exceeded: 15319 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15319 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61967 | 2 Miniorange, Wordpress | 2 Otp Verification, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. | ||||
| CVE-2026-66424 | 2 Cozyvision, Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-08-14 | 9.8 Critical |
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. | ||||
| CVE-2026-66429 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66430 | 2 Codepress It Solutions Llc, Wordpress | 2 Visitor Traffic Real Time Statistics Pro, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | ||||
| CVE-2026-66444 | 2 Kendysond, Wordpress | 2 Payment Forms For Paystack, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions. | ||||
| CVE-2026-66456 | 2 Bestwebsoft, Wordpress | 2 Profile Extra Fields, Wordpress | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | ||||
| CVE-2026-66461 | 2 Smepay, Wordpress | 2 Smepay:upi Gateway For Woocommerce, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions. | ||||
| CVE-2026-66467 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluentcommunity | 2026-08-14 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions. | ||||
| CVE-2026-66653 | 2 Edge-themes, Wordpress | 2 Barista, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions. | ||||
| CVE-2026-66656 | 2 Mikado-themes, Wordpress | 2 Foton Core, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions. | ||||
| CVE-2026-66657 | 2 Mikado-themes, Wordpress | 2 Biagiotti, Wordpress | 2026-08-14 | 8.1 High |
| Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions. | ||||
| CVE-2026-66658 | 2 Mvp Themes, Wordpress | 2 Reviewer, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-66704 | 2 Jegstudio, Wordpress | 2 Gutenverse, Wordpress | 2026-08-14 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions. | ||||
| CVE-2026-73188 | 2 Iqonic, Wordpress | 2 Kivicare, Wordpress | 2026-08-14 | N/A |
| This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610. | ||||
| CVE-2026-73340 | 2 Fifu, Wordpress | 2 Featured Image From Url, Wordpress | 2026-08-14 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions. | ||||
| CVE-2026-73346 | 2 Mailchimp, Wordpress | 2 Mailchimp For Woocommerce, Wordpress | 2026-08-14 | 7.6 High |
| Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | ||||
| CVE-2026-73353 | 2 Revolut, Wordpress | 2 Revolut Gateway For Woocommerce, Wordpress | 2026-08-14 | 5.3 Medium |
| Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions. | ||||
| CVE-2026-57804 | 2 Codexthemes, Wordpress | 2 Thegem Theme Elements (for Elementor), Wordpress | 2026-08-14 | 7.5 High |
| Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows PHP Local File Inclusion. This issue affects TheGem Theme Elements (for Elementor): from n/a before 5.12.1.1. | ||||
| CVE-2026-19794 | 2 Gamerz, Wordpress | 2 Wp-stats, Wordpress | 2026-08-14 | 7.2 High |
| The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-18109 | 2 Boldgrid, Wordpress | 2 W3 Total Cache, Wordpress | 2026-08-14 | 7.2 High |
| The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable when the Lazy Load Images feature of W3 Total Cache is enabled, as the unsafe re-emission occurs exclusively within the LazyLoad mutator's img tag rewriting step. | ||||