Export limit exceeded: 14330 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14330 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65505 | 2 Bdthemes, Wordpress | 2 Utlimate Store Kit Elementor Addons, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-57704 | 2 Storeapps, Wordpress | 2 Smart Manager, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | ||||
| CVE-2026-59547 | 2 Easy Payment, Wordpress | 2 Payment Gateway For Paypal On Woo Commerce, Wordpress | 2026-07-23 | 7.5 High |
| Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | ||||
| CVE-2026-65484 | 2 Analogwp, Wordpress | 2 Style Kits, Wordpress | 2026-07-23 | 6.3 Medium |
| Contributor Broken Access Control in Style Kits <= 2.6.5 versions. | ||||
| CVE-2026-65496 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-07-23 | 4.4 Medium |
| Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65497 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-07-23 | 7.2 High |
| Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-15646 | 2 Berocket, Wordpress | 2 Brands For Woocommerce, Wordpress | 2026-07-23 | 6.4 Medium |
| The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-25424 | 2 Mediavine, Wordpress | 2 Mediavine Control Panel, Wordpress | 2026-07-23 | 4.3 Medium |
| Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | ||||
| CVE-2026-57384 | 2 Membershipsoftware, Wordpress | 2 Wishlist Member X, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. | ||||
| CVE-2026-57735 | 2 Soflyy, Wordpress | 2 Breakdance, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions. | ||||
| CVE-2026-57809 | 2 Affiliatewp, Wordpress | 2 Affiliatewp, Wordpress | 2026-07-23 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions. | ||||
| CVE-2026-61950 | 2 Themetechmount, Wordpress | 2 Truebooker, Wordpress | 2026-07-23 | 9.3 Critical |
| Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | ||||
| CVE-2026-65449 | 2 Romancode, Wordpress | 2 Mapsvg, Wordpress | 2026-07-23 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | ||||
| CVE-2026-65487 | 2 Themegoods, Wordpress | 2 Photography, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | ||||
| CVE-2026-65519 | 2 Gt3themes, Wordpress | 2 Photo Gallery, Wordpress | 2026-07-23 | 6.5 Medium |
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||||
| CVE-2026-65512 | 2 Melapress, Wordpress | 2 Wp Activity Log, Wordpress | 2026-07-23 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. | ||||
| CVE-2026-65460 | 2 Wordpress, Zarinpal | 2 Wordpress, Zarinpal Gateway | 2026-07-23 | 4.3 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. | ||||
| CVE-2026-65453 | 2 Motovnet, Wordpress | 2 Ebook Store, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | ||||
| CVE-2026-15145 | 2 Wordpress, Wpdevteam | 2 Wordpress, Essential Addons For Elementor – Popular Elementor Templates & Widgets | 2026-07-23 | 6.4 Medium |
| The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Fancy Text Widget in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-27355 | 2 Metaphorcreations, Wordpress | 2 Ditty, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. | ||||