Export limit exceeded: 404441 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404441 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-91829 2026-10-11 7.1 High
The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators.
CVE-2026-89304 2026-10-11 6.5 Medium
The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform blind SQL injection attacks.
CVE-2026-89297 2026-10-11 8.6 High
The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-89287 2026-10-11 8.6 High
The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.
CVE-2026-89285 2026-10-11 8.6 High
The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database.
CVE-2026-89234 2026-10-11 8.6 High
The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-89232 2026-10-11 8.6 High
The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-89213 2026-10-11 8.6 High
The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
CVE-2026-89195 2026-10-11 8.6 High
The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database.
CVE-2026-88930 2026-10-11 8.6 High
The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-88827 2026-10-11 8.8 High
The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.
CVE-2026-88826 2026-10-11 8.8 High
The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen.
CVE-2026-87762 2026-10-11 8.8 High
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.
CVE-2026-87761 2026-10-11 8.0 High
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline script block on every front-end page, allowing any authenticated user, such as a subscriber, to perform Stored Cross-Site Scripting attacks against every visitor, including administrators.
CVE-2026-87760 2026-10-11 8.8 High
The Web Vitals Tracking WordPress plugin through 5.4.2 does not validate or escape performance measurements submitted by unauthenticated visitors before storing them and outputting them in a script context on an administrative page, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators.
CVE-2026-85126 2026-10-11 7.2 High
The Crowdfundly WordPress plugin through 2.2.2 does not have capability checks on some of its AJAX actions, allowing users holding one of its own low privileged roles to grant themselves the administrator role or arbitrary capabilities, leading to a full site takeover.
CVE-2026-84737 2026-10-11 9.8 Critical
The Freeton WP WordPress plugin through 1.0.0 does not correctly validate the activation code when authenticating a user, allowing unauthenticated attackers to log in as any user whose email address they know, including administrators.
CVE-2026-84734 2026-10-11 9.8 Critical
The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.
CVE-2026-84261 2026-10-11 8.8 High
The click5 CRM add-on to Contact Form 7 WordPress plugin through 1.0.4 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.
CVE-2026-84260 2026-10-11 8.8 High
The click5 CRM add-on to Gravity Forms WordPress plugin through 1.0.3 does not sanitise and escape content submitted through an unauthenticated endpoint before outputting it back in an admin page, leading to Stored XSS which could be used against high privilege users such as admin.