Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

12,997 CVEs

CVEs (12,997, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 12,997 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-13170 HIGH Patched 7.2 2026-08-10 The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level acc…
CVE-2026-13600 HIGH Patched 8.1 2026-08-10 The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie du…
CVE-2026-13701 MEDIUM Patched 4.8 2026-08-10 The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow admin…
CVE-2026-14206 HIGH Patched 7.5 2026-08-10 The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users …
CVE-2026-14211 LOW Patched 3.8 2026-08-10 The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose rec…
CVE-2026-14237 HIGH Patched 7.2 2026-08-10 The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API …
CVE-2026-14238 MEDIUM Patched 4.1 2026-08-10 The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its r…
CVE-2026-14293 HIGH Patched 8.8 2026-08-10 The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that valu…
CVE-2026-14860 MEDIUM Patched 5.3 2026-08-10 The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attack…
CVE-2026-14941 MEDIUM Patched 5.4 2026-08-10 The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users wi…
CVE-2026-15047 MEDIUM Patched 6.8 2026-08-10 The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contri…
CVE-2026-15229 MEDIUM 5.3 2026-08-10 The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at…
CVE-2026-15237 MEDIUM Patched 5.3 2026-08-10 The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing un…
CVE-2026-15238 MEDIUM Patched 5.4 2026-08-10 The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-priv…
CVE-2026-16257 HIGH Patched 8.2 2026-08-10 The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthent…
CVE-2026-16298 CRITICAL Patched 9.8 2026-08-10 The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary…
CVE-2026-16299 CRITICAL Patched 9.8 2026-08-10 The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of ar…
CVE-2026-16949 MEDIUM Patched 5.8 2026-08-10 The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to per…
CVE-2026-16985 HIGH Patched 8.8 2026-08-10 The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowin…
CVE-2026-17010 MEDIUM 5.4 2026-08-10 The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-leve…
CVE-2026-17012 MEDIUM 5.3 2026-08-10 The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the me…
CVE-2026-17016 LOW 3.7 2026-08-10 The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPa…
CVE-2026-17018 MEDIUM 4.9 2026-08-10 The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of it…
CVE-2026-17019 MEDIUM Patched 6.1 2026-08-10 The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, a…
CVE-2026-17020 MEDIUM 4.3 2026-08-10 The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a…