Export limit exceeded: 14743 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (14743 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-41560 2 Wordpress-extensions, Wxdlabs 2 Wxd Backup Lite, Wxd Backup Lite 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-105306 1 Redhat 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more 2026-10-06 6.5 Medium
A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process fails to filter security-sensitive client attributes when a new client is created. An attacker with a valid Initial Access Token can register a client that bypasses audience checks during token introspection. This allows the attacker to view sensitive identity information, roles, and session details from access tokens belonging to other applications in the same realm.
CVE-2026-39763 2 Deepak Anand, Wordpress-extensions 2 Wp Dummy Content Generator, Wp Dummy Content Generator 2026-10-06 4.3 Medium
Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: from n/a through 4.0.0.
CVE-2026-94669 2 Wordpress-extensions, Wpmanageninja 2 Fluent Forms Pro Add On Pack, Fluent Forms Pro Add On Pack 2026-10-06 5.3 Medium
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
CVE-2026-103684 2 Arraytics, Wordpress-extensions 2 Wp Event Solution, Wp Event Solution 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25.
CVE-2026-39783 2 Wordpress-extensions, Wp Syntex 2 Polylang, Polylang 2026-10-06 4.3 Medium
Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.
CVE-2026-105421 2 Nathanbarry, Wordpress-extensions 2 Kit (formerly Convertkit) For Woocommerce, Kit (formerly Convertkit) For Woocommerce 2026-10-06 5.3 Medium
Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0.
CVE-2026-104891 2 Douglasborthwick-crypto, Insumermodel 3 Mppx-condition-gate, Mppx-condition-gate, Mppx-token-gate 2026-10-06 7.5 High
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
CVE-2026-102780 1 Joomlafry.com 1 Tf Content For Joomla 2026-10-06 N/A
Joomla Extension - joomlafry.com - Unauthenticated cross-record publication and mass assignment in TF Content 2.9.0 - 2.9.4 - The extension unconditionally authorizes both creation and editing in its public `RecordController`. Its shared frontend save controller accepts the raw `jform` array, assigns the request-selected existing record ID, and saves it without filtering submitted properties through the configured form. A Guest can obtain a valid token from Joomla's public login form and modify any TF Content row, including mass-assigning `published`, `access`, and `created_by`.
CVE-2026-102779 1 Joomlafry.com 1 Tf Content For Joomla 2026-10-06 N/A
Joomla Extension - joomlafry.com - Unauthenticated forced execution of published automation tasks in TF Content 2.9.0 - 2.9.4 - The extension exposes the site task `records.custom_action` without authentication, ACL, CSRF, task-trigger, content-binding, or cron-token enforcement. A Guest can supply the numeric ID of any published TF Content task and make the component dispatch its configured executor immediately.
CVE-2026-103433 1 Docker 1 Buildx 2026-10-06 N/A
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.
CVE-2026-42637 2 Payplug, Wordpress-extensions 2 Payplug For Woocommerce (official), Payplug For Woocommerce (official) 2026-10-06 6.5 Medium
Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
CVE-2026-48199 2 Beplusthemes, Wordpress-extensions 2 Sermon'e, Sermon'e 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Sermon'e <= 1.0.2 versions.
CVE-2026-62072 2 Progress Planner, Wordpress-extensions 2 Progress Planner, Progress Planner 2026-10-06 8.8 High
Subscriber Broken Access Control in Progress Planner <= 1.10.0 versions.
CVE-2026-66588 2 Dream-theme, Wordpress-extensions 2 The7, The7 2026-10-06 7.5 High
Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.
CVE-2026-95526 2 Realmag777, Wordpress-extensions 2 Bear, Bear 2026-10-06 7.3 High
Unauthenticated Broken Access Control in BEAR <= 1.2.2 versions.
CVE-2026-102915 2 Marco Van Wieren, Wordpress-extensions 2 Wpo365, Wpo365 2026-10-06 8.5 High
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
CVE-2026-104387 2 Blubrry, Wordpress-extensions 2 Powerpress Podcasting, Powerpress Podcasting 2026-10-06 7.2 High
Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.
CVE-2026-104406 2 Picu, Wordpress-extensions 2 Picu, Picu 2026-10-06 7.3 High
Unauthenticated Broken Access Control in picu <= 3.10.1 versions.
CVE-2026-105059 2 Royalnavneet, Wordpress-extensions 2 Delete All Comments Of Wordpress, Delete All Comments Of Wordpress 2026-10-06 6.5 Medium
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.