Export limit exceeded: 16275 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (16275 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-64638 | 1 Wordpress | 1 Wordpress | 2026-08-24 | N/A |
| WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/). | ||||
| CVE-2026-65640 | 1 Wordpress | 1 Wordpress | 2026-08-24 | N/A |
| WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. | ||||
| CVE-2026-66636 | 2 Marcin, Wordpress | 2 Wise Chat, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-66641 | 2 Deepen Bajracharya, Wordpress | 2 Video Conferencing With Zoom, Wordpress | 2026-08-24 | 6.5 Medium |
| Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions. | ||||
| CVE-2026-66667 | 2 Wordpress, Wpdeveloper | 2 Wordpress, Templately | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | ||||
| CVE-2026-73345 | 2 Saad Iqbal, Wordpress | 2 License Manager For Woocommerce, Wordpress | 2026-08-24 | 7.1 High |
| Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | ||||
| CVE-2026-73365 | 2 Crocoblock. Jetimpex Inc., Wordpress | 2 Jetappointment, Wordpress | 2026-08-24 | 9.3 Critical |
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||||
| CVE-2026-73380 | 2 Supsysticcom, Wordpress | 2 Popup By Supsystic, Wordpress | 2026-08-24 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-73381 | 2 Supsysticcom, Wordpress | 2 Popup By Supsystic, Wordpress | 2026-08-24 | 9.1 Critical |
| Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | ||||
| CVE-2026-66599 | 2 Liquid Web / Stellarwp, Wordpress | 2 Wpcomplete, Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions. | ||||
| CVE-2026-66671 | 2 Elated-themes, Wordpress | 2 Verdure Core, Wordpress | 2026-08-24 | 8.1 High |
| Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions. | ||||
| CVE-2026-28153 | 2 Notification Master, Wordpress | 2 Notification Master – Real-time Wordpress Notifications With Email, Sms, Webhooks & More, Wordpress | 2026-08-24 | 7.5 High |
| Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions. | ||||
| CVE-2026-28171 | 2 Vanquish, Wordpress | 2 Woocommerce File Approval, Wordpress | 2026-08-24 | 8.6 High |
| Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | ||||
| CVE-2026-28190 | 2 Themebing, Wordpress | 2 Prolancer Element, Wordpress | 2026-08-24 | 7.1 High |
| Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions. | ||||
| CVE-2026-32471 | 2 Themebing, Wordpress | 2 Prolancer Element, Wordpress | 2026-08-24 | 8.5 High |
| Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions. | ||||
| CVE-2026-32476 | 2 Amplebyte Pvt Limited, Wordpress | 2 Brave Conversion Engine (pro), Wordpress | 2026-08-24 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions. | ||||
| CVE-2026-32558 | 2 Redefiningtheweb, Wordpress | 2 Affiliate Pro - Affiliate Program For Woocommerce & Wordpress, Wordpress | 2026-08-24 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions. | ||||
| CVE-2026-66585 | 2 Wordpress, Wpcafe | 2 Wordpress, Wp Cafe Pro | 2026-08-24 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions. | ||||
| CVE-2026-66587 | 2 Wordpress, Wpcafe | 2 Wordpress, Wp Cafe Pro | 2026-08-24 | 9.8 Critical |
| Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions. | ||||
| CVE-2026-66648 | 2 Mvpthemes, Wordpress | 2 Jawn, Wordpress | 2026-08-24 | 9.8 Critical |
| Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions. | ||||