Search
9,776 CVEs · Medium severity
CVEs (9,776, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 9,776 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84221 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to app… |
| CVE-2026-84022 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with… |
| CVE-2026-84021 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded,… |
| CVE-2026-83544 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contr… |
| CVE-2026-83543 | MEDIUM | Patched | 4.1 | 2026-09-05 | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above … |
| CVE-2026-82846 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing user… |
| CVE-2026-81424 | MEDIUM | Patched | 5.3 | 2026-09-05 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payme… |
| CVE-2026-81423 | MEDIUM | Patched | 4.3 | 2026-09-05 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect… |
| CVE-2026-78149 | MEDIUM | Patched | 5.3 | 2026-09-05 | The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenti… |
| CVE-2026-4361 | MEDIUM | 5.0 | 2026-09-05 | The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail… | |
| CVE-2026-3853 | MEDIUM | 6.4 | 2026-09-05 | The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions… | |
| CVE-2026-19861 | MEDIUM | Patched | 4.7 | 2026-09-05 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML … |
| CVE-2026-18843 | MEDIUM | 6.1 | 2026-09-05 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all vers… | |
| CVE-2026-15247 | MEDIUM | Patched | 5.4 | 2026-09-05 | The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers,… |
| CVE-2026-14975 | MEDIUM | 6.5 | 2026-09-05 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it poss… | |
| CVE-2026-8625 | MEDIUM | 6.4 | 2026-09-05 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML bl… | |
| CVE-2026-8623 | MEDIUM | 6.4 | 2026-09-05 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribut… | |
| CVE-2026-83628 | MEDIUM | 4.3 | 2026-09-05 | The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_… | |
| CVE-2026-18404 | MEDIUM | 6.4 | 2026-09-05 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all… | |
| CVE-2025-14945 | MEDIUM | 5.4 | 2026-09-05 | The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up … | |
| CVE-2026-86144 | MEDIUM | Patched | 5.6 | 2026-09-05 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE… |
| CVE-2026-86143 | MEDIUM | Patched | 6.9 | 2026-09-05 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for inte… |
| CVE-2026-86142 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. |
| CVE-2026-86139 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |
| CVE-2026-86138 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. |