Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

808 CVEs · Medium severity

CVEs (808, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 808 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84221 MEDIUM Patched 6.8 2026-09-05 The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to app…
CVE-2026-84022 MEDIUM Patched 6.8 2026-09-05 The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with…
CVE-2026-84021 MEDIUM Patched 6.8 2026-09-05 The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded,…
CVE-2026-83544 MEDIUM Patched 6.8 2026-09-05 The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contr…
CVE-2026-83543 MEDIUM Patched 4.1 2026-09-05 The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above …
CVE-2026-82846 MEDIUM Patched 6.8 2026-09-05 The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing user…
CVE-2026-81424 MEDIUM Patched 5.3 2026-09-05 The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payme…
CVE-2026-81423 MEDIUM Patched 4.3 2026-09-05 The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect…
CVE-2026-78149 MEDIUM Patched 5.3 2026-09-05 The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenti…
CVE-2026-4361 MEDIUM 5.0 2026-09-05 The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail…
CVE-2026-3853 MEDIUM 6.4 2026-09-05 The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions…
CVE-2026-19861 MEDIUM Patched 4.7 2026-09-05 The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML …
CVE-2026-18843 MEDIUM 6.1 2026-09-05 The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all vers…
CVE-2026-15247 MEDIUM Patched 5.4 2026-09-05 The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers,…
CVE-2026-14975 MEDIUM 6.5 2026-09-05 The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it poss…
CVE-2026-8625 MEDIUM 6.4 2026-09-05 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML bl…
CVE-2026-8623 MEDIUM 6.4 2026-09-05 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribut…
CVE-2026-83628 MEDIUM 4.3 2026-09-05 The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_…
CVE-2026-18404 MEDIUM 6.4 2026-09-05 The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all…
CVE-2025-14945 MEDIUM 5.4 2026-09-05 The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up …
CVE-2026-86144 MEDIUM Patched 5.6 2026-09-05 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE…
CVE-2026-86143 MEDIUM Patched 6.9 2026-09-05 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for inte…
CVE-2026-86142 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
CVE-2026-86139 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVE-2026-86138 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.