Export limit exceeded: 402870 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402870 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97300 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | ||||
| CVE-2026-97275 | 2026-10-06 | 5.3 Medium | ||
| Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | ||||
| CVE-2026-97257 | 2026-10-06 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7. | ||||
| CVE-2026-97071 | 2026-10-06 | 5.3 Medium | ||
| Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. | ||||
| CVE-2026-94299 | 2026-10-06 | 6.5 Medium | ||
| The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value. | ||||
| CVE-2026-94278 | 2026-10-06 | 5.5 Medium | ||
| The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. | ||||
| CVE-2026-93617 | 2026-10-06 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. | ||||
| CVE-2026-41563 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | ||||
| CVE-2026-41558 | 2026-10-06 | 7.5 High | ||
| Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | ||||
| CVE-2026-39791 | 2026-10-06 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. | ||||
| CVE-2026-39789 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | ||||
| CVE-2026-39760 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | ||||
| CVE-2026-39757 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. | ||||
| CVE-2026-39756 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions. | ||||
| CVE-2026-39755 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. | ||||
| CVE-2026-39754 | 2026-10-06 | 6.5 Medium | ||
| Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions. | ||||
| CVE-2026-39753 | 2026-10-06 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. | ||||
| CVE-2026-39752 | 2026-10-06 | 7.7 High | ||
| Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions. | ||||
| CVE-2026-39751 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | ||||
| CVE-2026-39750 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. | ||||