Export limit exceeded: 404437 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404437 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81156 | 2026-10-11 | 6.8 Medium | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing. | ||||
| CVE-2026-81155 | 2026-10-11 | 6.8 Medium | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators. | ||||
| CVE-2026-81154 | 2026-10-11 | 6.8 Medium | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators. | ||||
| CVE-2026-81153 | 2026-10-11 | 6.8 Medium | ||
| The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the gallery, including administrators, even where the unfiltered_html capability is disallowed such as on multisite. | ||||
| CVE-2026-78535 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions. | ||||
| CVE-2026-78534 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions. | ||||
| CVE-2026-78533 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions. | ||||
| CVE-2026-78532 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions. | ||||
| CVE-2026-78531 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions. | ||||
| CVE-2026-78529 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Alliance <= 3.11 versions. | ||||
| CVE-2026-66569 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions. | ||||
| CVE-2026-66568 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Original <= 1.9.0 versions. | ||||
| CVE-2026-66567 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions. | ||||
| CVE-2026-66566 | 2026-10-11 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Ambient <= 1.7 versions. | ||||
| CVE-2026-66565 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions. | ||||
| CVE-2026-66564 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions. | ||||
| CVE-2026-66563 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Windsor <= 2.10 versions. | ||||
| CVE-2026-66483 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions. | ||||
| CVE-2026-66482 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions. | ||||
| CVE-2026-62125 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions. | ||||