Export limit exceeded: 14417 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (14417 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65534 2 Charlie Etienne, Wordpress 2 Custom Links In Elementor Image Carousel, Wordpress 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65535 2 Takayuki Miyauchi, Wordpress 2 Tinymce Templates, Wordpress 2026-07-23 4.3 Medium
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65536 2 Mahdi Yousefi, Wordpress 2 افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری), Wordpress 2026-07-23 6.5 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65537 2 Themeisle, Wordpress 2 Cyr To Lat Reloaded – Transliteration Of Links And File Names, Wordpress 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65538 2 Nilo Velez, Wordpress 2 Machete, Wordpress 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65539 2 Bimal Rekhadiya, Wordpress 2 Kwayy Html Sitemap, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65540 2 Metin Saraç, Wordpress 2 Popup For Cf7 With Sweet Alert, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65550 2 Wordpress, Wpshopmart 2 Wordpress, Tabs 2026-07-23 5.9 Medium
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-61945 2 Multivendorx, Wordpress 2 Woocommerce Product Stock Alert, Wordpress 2026-07-23 6.5 Medium
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
CVE-2026-65450 2 Romancode, Wordpress 2 Mapsvg, Wordpress 2026-07-23 8.5 High
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-27403 2 Nerdpress, Wordpress 2 Hubbub Lites, Wordpress 2026-07-23 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.
CVE-2026-65050 2 Ninjaforms, Wordpress 2 Ninja Forms, Wordpress 2026-07-23 6.5 Medium
Ninja Forms WordPress plugin version 3.14.8 and prior contains a missing authorization vulnerability in the render callback of the `ninja-forms/submissions-table` Gutenberg block that allows authenticated attackers with Author-level privileges to expose stored form submissions to unauthenticated visitors by embedding the block with an arbitrary formID on a published post. Attackers can retrieve the signed bearer token injected into every page visitor's browser via `wp_localize_script` and use it against the REST API submissions endpoint to access all saved form submission field values, including sensitive personally identifiable information such as names, email addresses, and phone numbers.
CVE-2026-65452 2 Motovnet, Wordpress 2 Ebook Store, Wordpress 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65483 2 Hashthemes, Wordpress 2 Hashthemes Demo Importer, Wordpress 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
CVE-2026-65527 2 Lqd, Wordpress 2 Liquid Speech Balloon, Wordpress 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-59517 2 Hassantafreshi, Wordpress 2 Easy Form Builder, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-61951 2 Themetechmount, Wordpress 2 Truebooker, Wordpress 2026-07-23 9.8 Critical
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
CVE-2026-65462 2 Uncannyowl, Wordpress 2 Uncanny Automator, Wordpress 2026-07-23 7.6 High
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
CVE-2026-65480 2 Codexthemes, Wordpress 2 Thegem, Wordpress 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.
CVE-2026-13009 2 Wordpress, Wupsales 2 Wordpress, Ai Copilot – Content Generator 2026-07-23 6.5 Medium
The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The required waic-nonce is emitted on the front-end whenever the [waic_form] or [aiwu-form] shortcode is rendered, enabling contributor-level users who can publish shortcodes to obtain a valid nonce and reach the vulnerable AJAX handler, which performs no capability check beyond nonce verification when the shortcodes are not already embedded in a page.