Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-11997 | MEDIUM | 4.3 | 2026-06-24 | The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or incorrect nonce validatio… | |
| CVE-2026-12094 | MEDIUM | 5.3 | 2026-06-24 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_use… | |
| CVE-2026-12095 | HIGH | 7.2 | 2026-06-24 | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This makes it possi… | |
| CVE-2026-12100 | HIGH | 7.2 | 2026-06-24 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This makes it possible … | |
| CVE-2026-12416 | CRITICAL | 9.8 | 2026-06-24 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invo… | |
| CVE-2026-12417 | CRITICAL | 9.8 | 2026-06-24 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and includ… | |
| CVE-2026-13006 | NONE | — | 2026-06-24 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execut… | |
| CVE-2026-4297 | HIGH | 8.8 | 2026-06-24 | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capabili… | |
| CVE-2026-6292 | MEDIUM | 4.3 | 2026-06-24 | The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely bro… | |
| CVE-2026-7617 | MEDIUM | 5.3 | 2026-06-24 | The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying th… | |
| CVE-2026-8614 | MEDIUM | 4.3 | 2026-06-24 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin… | |
| CVE-2026-8617 | MEDIUM | 5.3 | 2026-06-24 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capabi… | |
| CVE-2026-8622 | MEDIUM | 6.1 | 2026-06-24 | The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to… | |
| CVE-2026-8628 | MEDIUM | 6.1 | 2026-06-24 | The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficien… | |
| CVE-2026-8688 | MEDIUM | 4.3 | 2026-06-24 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve… | |
| CVE-2026-8690 | MEDIUM | 5.3 | 2026-06-24 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the p… | |
| CVE-2026-8705 | HIGH | 7.5 | 2026-06-24 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions… | |
| CVE-2026-8865 | MEDIUM | 6.4 | 2026-06-24 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and in… | |
| CVE-2026-8896 | MEDIUM | 6.4 | 2026-06-24 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_tex… | |
| CVE-2026-8905 | MEDIUM | 6.1 | 2026-06-24 | The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect … | |
| CVE-2026-9172 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability … | |
| CVE-2026-9175 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This… | |
| CVE-2026-9178 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/… | |
| CVE-2026-9179 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc… | |
| CVE-2026-9183 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block… |