Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8899 | MEDIUM | 6.4 | 2026-05-27 | The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in all versions up to, and including, 1.0. This is due t… | |
| CVE-2026-8898 | MEDIUM | 6.4 | 2026-05-27 | The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This is due to in… | |
| CVE-2026-8897 | MEDIUM | 6.4 | 2026-05-27 | The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 0.1.9.5 due to insuffic… | |
| CVE-2026-8896 | MEDIUM | 6.4 | 2026-06-24 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_tex… | |
| CVE-2026-8895 | MEDIUM | 6.4 | 2026-06-09 | The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and including, 1.3. This is… | |
| CVE-2026-8894 | MEDIUM | 6.4 | 2026-05-27 | The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This is due… | |
| CVE-2026-8893 | MEDIUM | 6.4 | 2026-06-06 | The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up t… | |
| CVE-2026-8892 | MEDIUM | 6.4 | 2026-07-03 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all v… | |
| CVE-2026-8891 | MEDIUM | 6.4 | 2026-05-27 | The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, 1.1.0. This is due to i… | |
| CVE-2026-8887 | MEDIUM | 6.4 | 2026-05-27 | The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1.0. This is due to insu… | |
| CVE-2026-8886 | MEDIUM | 6.4 | 2026-05-27 | The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in versions up to, and including, 1.0. This is due to ins… | |
| CVE-2026-8885 | MEDIUM | 6.4 | 2026-06-02 | The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, … | |
| CVE-2026-8884 | MEDIUM | 6.4 | 2026-05-27 | The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.3.4 d… | |
| CVE-2026-8883 | MEDIUM | 6.4 | 2026-06-09 | The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up to, and including, 1.2. … | |
| CVE-2026-8882 | MEDIUM | 6.4 | 2026-06-09 | The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.1 du… | |
| CVE-2026-8880 | MEDIUM | 6.4 | 2026-06-09 | The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the romancart_button shortco… | |
| CVE-2026-8877 | MEDIUM | 6.4 | 2026-05-27 | The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is… | |
| CVE-2026-8875 | MEDIUM | 6.4 | 2026-05-27 | The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, and inclu… | |
| CVE-2026-8873 | MEDIUM | 6.4 | 2026-05-27 | The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 2.4.1 due to insuffic… | |
| CVE-2026-8872 | MEDIUM | 6.4 | 2026-05-27 | The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up to, and including, 1.0.… | |
| CVE-2026-8871 | MEDIUM | 6.4 | 2026-05-27 | The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is … | |
| CVE-2026-8870 | MEDIUM | 6.4 | 2026-05-27 | The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and inc… | |
| CVE-2026-8869 | MEDIUM | 6.4 | 2026-05-27 | The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and including, 1.2.1. This is… | |
| CVE-2026-8868 | MEDIUM | 6.4 | 2026-05-27 | The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, and including, 1.4. This … | |
| CVE-2026-8867 | MEDIUM | 6.4 | 2026-05-27 | The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versions up to, and includin… |