Export limit exceeded: 403624 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 403624 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403624 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-104652 | 1 Wordpress-extensions | 1 Envira Gallery | 2026-10-09 | 6.8 Medium |
| The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page embedding the gallery. | ||||
| CVE-2026-104653 | 1 Wordpress-extensions | 1 Envira Gallery | 2026-10-09 | 6.8 Medium |
| The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an image tag attribute, allowing users with the Author role and above to inject arbitrary web scripts that execute when any visitor, including an administrator, views a page containing the affected gallery. | ||||
| CVE-2026-104667 | 1 Wordpress-extensions | 1 Animated Number Counters | 2026-10-09 | 6.8 Medium |
| The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data including password hashes. | ||||
| CVE-2026-104677 | 1 Wordpress-extensions | 1 Wp Coder | 2026-10-09 | 7.2 High |
| The WP Coder WordPress plugin before 4.5.2 does not restrict access to its PHP code-execution feature to administrators, gating it on a content capability that the Editor role holds by default, which allows Editor-level users to save and execute arbitrary PHP code on the server and fully compromise the site. | ||||
| CVE-2026-104678 | 1 Wordpress-extensions | 1 Cp Media Player | 2026-10-09 | 2.7 Low |
| The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that should require administrator access. | ||||
| CVE-2026-104953 | 1 Wordpress-extensions | 1 Mpg | 2026-10-09 | 6.8 Medium |
| The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users with the Editor role or higher to perform SQL injection attacks and read sensitive data such as password hashes. | ||||
| CVE-2026-105316 | 1 Wordpress-extensions | 1 Magee Shortcodes | 2026-10-09 | 7.1 High |
| The Magee Shortcodes WordPress plugin through 2.1.1 does not sanitise and escape user input in some of its AJAX actions, which are available to unauthenticated users, before reflecting it back in the response, leading to Reflected Cross-Site Scripting. | ||||
| CVE-2026-86816 | 1 Wordpress-extensions | 1 Wpcafe | 2026-10-09 | 5.3 Medium |
| The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, including per-product sales counts, exact stock levels, and private product meta, that WooCommerce itself keeps behind authentication. | ||||
| CVE-2026-87782 | 1 Wordpress-extensions | 1 Koinonia Link | 2026-10-09 | 8.8 High |
| The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role. | ||||
| CVE-2026-87971 | 1 Wordpress-extensions | 1 If-so Dynamic Content | 2026-10-09 | 7.1 High |
| The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link. | ||||
| CVE-2026-96530 | 1 Wordpress-extensions | 1 Optimole | 2026-10-09 | 6.5 Medium |
| The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any authenticated user, including Subscribers, to read the site's third-party service credentials. | ||||
| CVE-2026-97188 | 1 Wordpress-extensions | 1 String Locator | 2026-10-09 | 8.8 High |
| The String locator WordPress plugin before 2.6.8 does not restrict the classes allowed when deserializing the content of a database row saved through its database editor, allowing unauthenticated attackers to store a serialized PHP object that is instantiated when an administrator later opens and saves that row. If a suitable POP chain is present via another installed String locator WordPress plugin before 2.6.8 or , this can lead to arbitrary file deletion, sensitive data disclosure or remote code execution. | ||||
| CVE-2026-97331 | 1 Wordpress-extensions | 1 User Private Files | 2026-10-09 | 4.3 Medium |
| The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators. | ||||
| CVE-2026-97354 | 1 Wordpress-extensions | 1 Powerpress | 2026-10-09 | 4.1 Medium |
| The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users with the contributor role and above to perform Server-Side Request Forgery attacks against internal services. | ||||
| CVE-2026-86833 | 1 Wordpress-extensions | 1 Metform | 2026-10-09 | 5.4 Medium |
| The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | ||||
| CVE-2026-105322 | 1 Wordpress-extensions | 1 Magee Shortcodes | 2026-10-09 | 5.3 Medium |
| The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary emails to any address through the site (mail relay). | ||||
| CVE-2026-82211 | 1 Wordpress-extensions | 1 Nexi Xpay Build | 2026-10-09 | 8.2 High |
| The Nexi XPay Build WordPress plugin through 7.6.2 does not verify the payment result supplied to several of its unauthenticated routes, allowing attackers to mark arbitrary orders as paid or failed, to cancel them, and to obtain order keys which expose guest buyers' details. | ||||
| CVE-2026-82212 | 1 Wordpress-extensions | 1 Nexi Xpay Build | 2026-10-09 | 7.5 High |
| The Nexi XPay Build WordPress plugin through 7.6.2 does not correctly validate the security token on its payment notification route, accepting the request when the target order has no stored token, which allows unauthenticated attackers to mark arbitrary orders as paid, or to mark genuinely paid orders as failed. | ||||
| CVE-2026-102781 | 1 Ordasoft.com | 1 Touch Slider Extension For Joomla | 2026-10-09 | N/A |
| Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path. | ||||
| CVE-2026-78013 | 2026-10-09 | 5.2 Medium | ||
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Protection mechanism bypass. | ||||