Export limit exceeded: 398493 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96533 | 1 Wordpress-extensions | 1 Testimonials Widget | 2026-09-26 | 5.8 Medium |
| The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses. | ||||
| CVE-2026-96532 | 1 Wordpress-extensions | 1 Testimonials Widget | 2026-09-26 | 7.5 High |
| The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post. | ||||
Page 1 of 1.