Export limit exceeded: 398587 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (398587 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-15696 | 1 Wordpress-extensions | 1 Real3d Flipbook Lite | 2026-09-27 | 6.8 Medium |
| The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for editing, including administrators. | ||||
| CVE-2026-14321 | 1 Wordpress-extensions | 1 Divi Dash | 2026-09-27 | 8.2 High |
| The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service. | ||||
| CVE-2026-16264 | 1 Wordpress-extensions | 1 Newsletters | 2026-09-27 | 6.5 Medium |
| The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address. | ||||
| CVE-2026-18364 | 1 Wordpress-extensions | 1 Zportals | 2026-09-27 | 4.3 Medium |
| The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2's stored integration settings. | ||||
| CVE-2026-18365 | 1 Wordpress-extensions | 1 Zportals | 2026-09-27 | 4.3 Medium |
| The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user, including administrators. | ||||
| CVE-2026-75799 | 1 Wordpress-extensions | 1 Yahman Add-ons | 2026-09-27 | 9 Critical |
| The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled. | ||||
| CVE-2026-84091 | 1 Wordpress-extensions | 1 Sumit Payment Gateway For Woocommerce | 2026-09-27 | 5.3 Medium |
| The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment. | ||||
| CVE-2026-88974 | 2 Wordpress-extensions, Wpgraphql | 2 Wpgraphql, Wpgraphql | 2026-09-27 | 5.4 Medium |
| WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2. | ||||
| CVE-2026-77421 | 1 Jline | 1 Jline | 2026-09-27 | 6.5 Medium |
| JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jline/builtins/Nano.java to Java's backtracking regular expression engine without a timeout or backtracking bound. A nested-quantifier expression evaluated against non-matching buffer content can consume excessive CPU and indefinitely block the editor session thread, and remote multi-user deployments can lose a worker thread for each affected session. This issue is fixed in versions 3.30.15 and 4.3.1. | ||||
| CVE-2026-77422 | 1 Jline | 1 Jline | 2026-09-27 | 7.5 High |
| JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(...) and, unless line-regexp mode is used, automatically adds a dot-star prefix and suffix before compiling it with Java's backtracking regular expression engine. The wrapping expands the backtracking search space, so a short nested-quantifier expression evaluated against non-matching input can consume excessive CPU and indefinitely block a command worker, including in remotely exposed shell sessions. This issue is fixed in versions 3.30.15 and 4.3.1. | ||||
| CVE-2026-77420 | 1 Jline | 1 Jline | 2026-09-27 | 5.5 Medium |
| JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1. | ||||
| CVE-2026-93620 | 2 Payplus, Wordpress-extensions | 2 Payplus Payment Gateway, Payplus Payment Gateway | 2026-09-27 | 6.5 Medium |
| Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | ||||
| CVE-2026-93773 | 2 Wobbie, Wordpress-extensions | 2 Mollie Forms, Mollie Forms | 2026-09-27 | 8.5 High |
| Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. | ||||
| CVE-2026-94079 | 2 Wordpress-extensions, Wpusermanager | 2 Wp User Manager, Wp User Manager | 2026-09-27 | 5.3 Medium |
| Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. | ||||
| CVE-2026-95528 | 2 Magazine3, Wordpress-extensions | 2 Core Web Vitals & Pagespeed Booster, Core Web Vitals& Pagespeed Booster | 2026-09-27 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | ||||
| CVE-2026-95530 | 2 Pixelyoursite, Wordpress-extensions | 2 Pixelyoursite – Your Smart Pixel (tag) Manager, Pixelyoursite | 2026-09-27 | 6.5 Medium |
| Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. | ||||
| CVE-2026-100749 | 2026-09-27 | N/A | ||
| Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted. | ||||
| CVE-2026-95592 | 2 Radiustheme, Wordpress-extensions | 2 Team, Team | 2026-09-27 | 5.3 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. | ||||
| CVE-2026-95600 | 2 Trustedlogin, Wordpress-extensions | 2 Trustedlogin, Trustedlogin Connector | 2026-09-27 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. | ||||
| CVE-2026-95602 | 2 Wordpress-extensions, Yithemes | 2 Yith Woocommerce Request A Quote, Yith Woocommerce Request A Quote | 2026-09-27 | 6.5 Medium |
| Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1. | ||||