Export limit exceeded: 402638 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402638 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-93617 | 2026-10-06 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. | ||||
| CVE-2026-89289 | 2026-10-06 | 5.3 Medium | ||
| The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the courier status and customer-facing tracking details of any WooCommerce order by supplying its id. | ||||
| CVE-2026-86786 | 2026-10-06 | 5.3 Medium | ||
| The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions and media metadata. | ||||
| CVE-2026-41563 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | ||||
| CVE-2026-41558 | 2026-10-06 | 7.5 High | ||
| Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | ||||
| CVE-2026-39791 | 2026-10-06 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. | ||||
| CVE-2026-39789 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | ||||
| CVE-2026-39760 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | ||||
| CVE-2026-39757 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. | ||||
| CVE-2026-39756 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions. | ||||
| CVE-2026-39755 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. | ||||
| CVE-2026-39754 | 2026-10-06 | 6.5 Medium | ||
| Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions. | ||||
| CVE-2026-39753 | 2026-10-06 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. | ||||
| CVE-2026-39752 | 2026-10-06 | 7.7 High | ||
| Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions. | ||||
| CVE-2026-39751 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||
| CVE-2026-39750 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. | ||||
| CVE-2026-39749 | 2026-10-06 | 6.5 Medium | ||
| Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions. | ||||
| CVE-2026-39748 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in EduMall <= 4.5.3 versions. | ||||
| CVE-2026-39747 | 2026-10-06 | 8.5 High | ||
| Subscriber SQL Injection in Woffice <= 5.4.35 versions. | ||||
| CVE-2026-39746 | 2026-10-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. | ||||