Export limit exceeded: 16587 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16587 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2016-20079 | 2 Jamie, Wordpress | 2 Dharma Booking, Wordpress | 2026-06-23 | 6.2 Medium |
| WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway parameter in proccess.php to read sensitive files like configuration and system files. | ||||
| CVE-2016-20080 | 2 Brandfolder, Wordpress | 2 Brandfolder, Wordpress | 2026-06-23 | 6.2 Medium |
| WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_abspath parameter to read sensitive files like wp-config.php or execute remote code. | ||||
| CVE-2016-20082 | 2 Abtest, Wordpress | 2 Abtest, Wordpress | 2026-06-23 | 6.2 Medium |
| WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code. | ||||
| CVE-2025-60175 | 2 Vynnus, Wordpress | 2 Popad, Wordpress | 2026-06-23 | 4.4 Medium |
| Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions. | ||||
| CVE-2026-48836 | 2 Mantrabrain, Wordpress | 2 Easy Invoice, Wordpress | 2026-06-23 | 10 Critical |
| Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | ||||
| CVE-2026-49774 | 2 Filipe Nasc, Wordpress | 2 Rd Station, Wordpress | 2026-06-23 | 9.9 Critical |
| Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. | ||||
| CVE-2025-58924 | 2 Themerex Group, Wordpress | 2 Geya, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Geya <= 1.15 versions. | ||||
| CVE-2025-60085 | 2 Themerex Group, Wordpress | 2 Learnify, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions. | ||||
| CVE-2025-69107 | 2 Themerex, Wordpress | 2 Rosaleen, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions. | ||||
| CVE-2025-69109 | 2 Themerex, Wordpress | 2 Raider Spirit, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions. | ||||
| CVE-2025-69119 | 2 Themerex, Wordpress | 2 Corbesier, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Corbesier <= 1.15.0 versions. | ||||
| CVE-2025-69121 | 2 Themerex, Wordpress | 2 Deliciosa, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Deliciosa <= 1.10.0 versions. | ||||
| CVE-2025-69125 | 2 Themerex, Wordpress | 2 Food Drop, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Food Drop <= 1.3 versions. | ||||
| CVE-2025-69136 | 2 Themelogi, Wordpress | 2 Wanium, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Wanium <= 1.9.8 versions. | ||||
| CVE-2025-69141 | 2 Themerex, Wordpress | 2 Kelly Young, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Kelly Young <= 1.1.0 versions. | ||||
| CVE-2025-69149 | 2 Themerex, Wordpress | 2 Top Dog, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Top Dog <= 1.0.5 versions. | ||||
| CVE-2025-69177 | 2 Themelogi, Wordpress | 2 Roneous, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Roneous <= 2.1.5 versions. | ||||
| CVE-2025-69178 | 2 Cactusthemes, Wordpress | 2 Truemag, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Truemag <= 4.3.14.2 versions. | ||||
| CVE-2026-34893 | 2 Webgeniuslab, Wordpress | 2 Thegov Core, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Thegov Core < 2.0.23 versions. | ||||
| CVE-2026-34894 | 2 Webgeniuslab, Wordpress | 2 Integrio Core, Wordpress | 2026-06-23 | 8.1 High |
| Unauthenticated Local File Inclusion in Integrio Core < 1.2.8 versions. | ||||