| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS.
This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. |
| Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions. |
| Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. |
| An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected. |
| Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions. |
| Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions. |
| Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions. |
| Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions. |
| Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions. |
| Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. |
| Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. |
| Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. |
| Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. |
| Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. |
| Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions. |
| Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. |
| Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. |
| Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-upgrade workflow changes via sending a crafted POST request to /cgi-bin/cstecgi.cgi. |