Export limit exceeded: 404423 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404423 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-6243 2026-10-11 6.4 Medium
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kses bypass / mutation XSS in all versions up to, and including, 3.28.36. This is due to the 'get_dynamic_values' function performing text-level find-and-replace operations on post content without HTML-aware parsing. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-66481 2026-10-11 6.8 Medium
Author Arbitrary File Deletion in Presto Player Pro <= 3.0.1 versions.
CVE-2026-66435 2026-10-11 5.9 Medium
Insertion of Sensitive Information Into Sent Data vulnerability in Devin Walker WP Rollback wp-rollback allows Retrieve Embedded Sensitive Data.This issue affects WP Rollback: from n/a through 3.1.2.
CVE-2026-65459 2026-10-11 7.5 High
Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions.
CVE-2026-62130 2026-10-11 7.2 High
Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions.
CVE-2026-62129 2026-10-11 9.9 Critical
Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions.
CVE-2026-62118 2026-10-11 7.3 High
Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions.
CVE-2026-62098 2026-10-11 6.5 Medium
Unauthenticated Content Injection in Boutique <= 2.3.3 versions.
CVE-2026-62046 2 Themerex Group, Wordpress-extensions 2 Gutentype, Gutentype 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
CVE-2026-62045 2 Themerex Group, Wordpress-extensions 2 Booklovers, Booklovers 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
CVE-2026-62044 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
CVE-2026-62038 2026-10-11 7.3 High
Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
CVE-2026-62035 2026-10-11 6.3 Medium
Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.
CVE-2026-62033 2026-10-11 7.6 High
Subscriber Settings Change in uListing <= 2.2.0 versions.
CVE-2026-62028 2026-10-11 5.4 Medium
Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Before After Image Comparison – Image comparison for WP: from n/a through 1.1.21.
CVE-2026-62025 2026-10-11 9 Critical
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
CVE-2026-62024 2026-10-11 9.9 Critical
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
CVE-2026-62022 2026-10-11 9.8 Critical
Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
CVE-2026-62021 2026-10-11 8.8 High
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
CVE-2026-5725 2026-10-11 6.1 Medium
The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.