Export limit exceeded: 102522 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (102522 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94121 2026-09-30 8.8 High
Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.
CVE-2026-94120 2026-09-30 7.5 High
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-94115 2026-09-30 8.5 High
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
CVE-2026-94082 2026-09-30 7.6 High
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-94081 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
CVE-2026-94078 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94076 2026-09-30 8.8 High
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
CVE-2026-93771 2026-09-30 7.2 High
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93770 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-93651 2026-09-30 7.2 High
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93624 2026-09-30 7.2 High
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-93621 2026-09-30 8.2 High
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-93514 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93512 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-91832 2026-09-30 7.1 High
The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP Mobile Menu WordPress plugin before 2.9 settings through a cross-site request in an administrator's session, and the imported values are then output unescaped to every visitor, resulting in Stored Cross-Site Scripting.
CVE-2026-89193 2026-09-30 7.5 High
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of any user viewing an affected page, including administrators.
CVE-2026-88797 2026-09-30 7.1 High
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
CVE-2026-62085 2026-09-30 7.6 High
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
CVE-2026-27371 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-102909 1 Sourcecodester 1 Online Reviewer Management System 2026-09-30 7.3 High
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.