Export limit exceeded: 402651 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (402651 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-39788 2 Shamimsplugins, Wordpress-extensions 2 Front End Pm, Front End Pm 2026-10-06 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions.
CVE-2026-39790 2 E4jvikwp, Wordpress-extensions 2 Vikrentcar, Vikrentcar 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions.
CVE-2026-39792 2 Mitchell Bennis, Wordpress-extensions 2 Simple File List, Simple File List 2026-10-06 8.6 High
Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.
CVE-2026-39793 2 Nicu Micle, Wordpress-extensions 2 Simple Jwt Login, Simple Jwt Login 2026-10-06 8.8 High
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-39794 2 Wclovers, Wordpress-extensions 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.
CVE-2026-39795 2 Brewlabs, Wordpress-extensions 2 Sendpress Newsletters, Sendpress Newsletters 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
CVE-2026-39796 2 Flipper Code, Wordpress-extensions 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
CVE-2026-39797 2 Data443, Wordpress-extensions 2 Gdpr Framework By Data443, Gdpr Framework By Data443 2026-10-06 9.8 Critical
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
CVE-2026-39798 2 Themetechmount, Wordpress-extensions 2 Truebooker, Truebooker 2026-10-06 6.5 Medium
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVE-2026-40806 2 Plugin-devs, Wordpress-extensions 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
CVE-2026-40807 2 Aman, Wordpress-extensions 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions.
CVE-2026-41555 2 Weblizar, Wordpress-extensions 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
CVE-2026-41559 2 Pluginjoy, Wordpress-extensions 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions.
CVE-2026-41560 2 Wordpress-extensions, Wxdlabs 2 Wxd Backup Lite, Wxd Backup Lite 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-41561 2 Adrian Lin, Wordpress-extensions 2 Museder Restoreone, Museder Restoreone 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.
CVE-2026-41562 2 Norvisgabriel, Wordpress-extensions 2 Norvis Backup, Norvis Backup 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
CVE-2026-42413 2 Daftplug, Wordpress-extensions 2 Snapshotify, Snapshotify 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions.
CVE-2026-106503 2026-10-06 8.1 High
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
CVE-2026-97626 2026-10-06 N/A
Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility check that the profile page and the `.rss` and `.atom` routes apply. Anonymous users, restricted users and non-members could confirm the existence of limited or private users and private organizations and read their profile details and public activity, also when `[other] ENABLE_FEED` was disabled. Activity in private repositories was not included.
CVE-2026-96594 2026-10-06 N/A
The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response without the content type and disposition headers Gitea uses for user content. An HTML file committed to a repository was therefore rendered by the browser on the Gitea origin. A user who can push to a repository could run JavaScript in the session of a victim who opens the media URL and act with the victim's permissions.