Export limit exceeded: 404442 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404442 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93883 | 2026-10-11 | 6.4 Medium | ||
| The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone' parameter in all versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only exploitable on sites where the 'Force Bootstrap' miscellaneous setting (acadp_misc_settings['force_bootstrap']) is enabled and the 'ACADP Listing Address' widget is placed on a sidebar displayed on single listing pages; both conditions are non-default. | ||||
| CVE-2026-93775 | 2026-10-11 | 7.2 High | ||
| The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Auphonic Webhook in all versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injection is triggered by submitting a request to the Auphonic webhook endpoint with any POST body where the status_string field is not the literal string 'Done', causing the full raw POST superglobal to be stored in the plugin log before any authentication key validation is performed. | ||||
| CVE-2026-91862 | 2026-10-11 | 6.4 Medium | ||
| The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-image-points' parameter in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-89100 | 2026-10-11 | 6.1 Medium | ||
| The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '#response' URL Fragment in all versions up to, and including, 4.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires that the 'Generic Errors' setting is unchecked, causing getErrorMessage() to return the raw Stripe error string unchanged rather than substituting a mapped safe message. | ||||
| CVE-2026-87869 | 2026-10-11 | 6.1 Medium | ||
| The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link. | ||||
| CVE-2026-78530 | 2026-10-11 | 7.7 High | ||
| Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions. | ||||
| CVE-2026-78068 | 2026-10-11 | 6.4 Medium | ||
| The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-6243 | 2026-10-11 | 6.4 Medium | ||
| The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-66481 | 2026-10-11 | 6.8 Medium | ||
| Author Arbitrary File Deletion in Presto Player Pro <= 3.0.1 versions. | ||||
| CVE-2026-66435 | 2026-10-11 | 5.9 Medium | ||
| Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This issue affects WP Rollback: from n/a through 3.1.2. | ||||
| CVE-2026-65459 | 2026-10-11 | 7.5 High | ||
| Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions. | ||||
| CVE-2026-62130 | 2026-10-11 | 7.2 High | ||
| Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions. | ||||
| CVE-2026-62129 | 2026-10-11 | 9.9 Critical | ||
| Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions. | ||||
| CVE-2026-62118 | 2026-10-11 | 7.3 High | ||
| Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions. | ||||
| CVE-2026-62098 | 2026-10-11 | 6.5 Medium | ||
| Unauthenticated Content Injection in Boutique <= 2.3.3 versions. | ||||
| CVE-2026-62046 | 2 Themerex Group, Wordpress-extensions | 2 Gutentype, Gutentype | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12. | ||||
| CVE-2026-62045 | 2 Themerex Group, Wordpress-extensions | 2 Booklovers, Booklovers | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0. | ||||
| CVE-2026-62044 | 2026-10-11 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13. | ||||
| CVE-2026-62038 | 2026-10-11 | 7.3 High | ||
| Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions. | ||||
| CVE-2026-62035 | 2026-10-11 | 6.3 Medium | ||
| Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions. | ||||