Export limit exceeded: 401118 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (10357 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-83555 | 1 Wordpress-extensions | 1 Email Subscribers By Icegram Express | 2026-09-28 | 5.3 Medium |
| The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know. | ||||
| CVE-2026-84027 | 1 Wordpress-extensions | 1 Directorist | 2026-09-28 | 4.3 Medium |
| The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users. | ||||
| CVE-2026-86842 | 1 Wordpress-extensions | 1 Real3d Flipbook Lite | 2026-09-28 | 6.8 Medium |
| The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store JavaScript that executes in the context of any visitor or administrator viewing the site. | ||||
| CVE-2026-87069 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 3.1 Low |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before running a one-time payment-field migration during the construction of one of its admin screens, and that construction happens on every wp-admin request for any logged-in user. Any authenticated user, including a Subscriber with no permissions in the Forminator Forms WordPress plugin before 1.57.2.1, can therefore rewrite the saved field configuration of any form on the site, including a live payment form. | ||||
| CVE-2026-87074 | 1 Wordpress-extensions | 1 Forminator Forms | 2026-09-28 | 3.7 Low |
| The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who created the draft, and takes both the recipient address and the link written into the message from the request, so unauthenticated visitors can make the site send a message from its own mail configuration to any address, carrying a link of their choosing inside the site's own template. The token that authorises the send is handed to the anonymous caller by the Forminator Forms WordPress plugin before 1.57.2.1 itself and can be replayed without limit. | ||||
| CVE-2026-87979 | 1 Wordpress-extensions | 1 Paymob For Woocommerce | 2026-09-28 | 5.3 Medium |
| The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers to write a card-token record to any user's account and to enumerate registered accounts. | ||||
| CVE-2026-87981 | 1 Wordpress-extensions | 1 Paymob For Woocommerce | 2026-09-28 | 4.7 Medium |
| The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing users with contributor-level access to delete, wipe, or modify that configuration, including the stored payment credentials. | ||||
| CVE-2026-93507 | 1 Wordpress-extensions | 1 Wc Fields Factory | 2026-09-28 | 3.3 Low |
| The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy. | ||||
| CVE-2026-93508 | 1 Wordpress-extensions | 1 Wc Fields Factory | 2026-09-28 | 8.1 High |
| The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price. | ||||
| CVE-2026-93510 | 1 Wordpress-extensions | 1 Points And Rewards For Woocommerce | 2026-09-28 | 4.3 Medium |
| The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a companion wallet Points and Rewards for WooCommerce WordPress plugin before 2.10.4 is active, wallet balance. | ||||
| CVE-2026-6831 | 2 Vsourz, Wordpress-extensions | 2 Advanced Contact Form 7 Db, Advanced Contact Form 7 Db | 2026-09-28 | 6.5 Medium |
| The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to read all Contact Form 7 submission data via the 'acf7db' shortcode. | ||||
| CVE-2026-87848 | 1 Wordpress-extensions | 1 Mpcx Lightbox | 2026-09-28 | 3.7 Low |
| The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its AJAX actions available to unauthenticated users, nor does it check the status of the requested post, allowing unauthenticated visitors to retrieve the title, content or excerpt of arbitrary posts, including private, draft, pending, trashed and password-protected ones. | ||||
| CVE-2026-97176 | 1 Redhat | 3 Build Keycloak, Red Hat Single Sign On, Single Sign-on | 2026-09-28 | 4.2 Medium |
| A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active session at a lower level. Due to a logic error in how session re-evaluations are handled, Keycloak may incorrectly issue a token at the lower security level instead of enforcing the required higher level, potentially allowing unauthorized access to sensitive resources that rely on these security claims. | ||||
| CVE-2026-97177 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-09-28 | 6.6 Medium |
| A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This allows a delegated administrator, who should be restricted from resetting passwords, to change a user's credentials and take over their account. | ||||
| CVE-2026-3253 | 2 Mailerlite, Wordpress-extensions | 2 Mailerlite Signup Forms, Mailerlite-signup Forms | 2026-09-28 | 4.3 Medium |
| The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level access and above, to create or delete arbitrary signup forms. | ||||
| CVE-2026-4806 | 2 Alexvtn, Wordpress-extensions | 2 Custom Thank You Page For Woocommerce, Custom Thank You Page For Woocommerce | 2026-09-28 | 6.5 Medium |
| The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to to export or reset(delete) the plugin's settings. | ||||
| CVE-2026-89300 | 1 Wordpress-extensions | 1 Wp Verify Api | 2026-09-28 | 5.3 Medium |
| The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either. | ||||
| CVE-2026-96538 | 1 Enterprisedb | 1 Warehousepg | 2026-09-28 | N/A |
| WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally. | ||||
| CVE-2026-97311 | 1 Redhat | 4 Build Keycloak, Build Of Keycloak, Red Hat Single Sign On and 1 more | 2026-09-28 | 4.3 Medium |
| A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups. | ||||
| CVE-2026-92470 | 1 Gitlab | 1 Gitlab | 2026-09-28 | 7.7 High |
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces through the Duo AI troubleshooting feature due to missing authorization checks. | ||||