87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,001–1,050 of 87,929 · page 21 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-97308 | CVE-2026-97308 CVSS 4.8 | Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions. |
| CVE-2026-97307 | CVE-2026-97307 CVSS 7.5 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sens… |
| CVE-2026-97305 | CVE-2026-97305 | Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Config… |
| CVE-2026-97304 | CVE-2026-97304 CVSS 6.5 | Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects T… |
| CVE-2026-97303 | CVE-2026-97303 CVSS 7.6 | Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly… |
| CVE-2026-97302 | CVE-2026-97302 CVSS 5.3 | Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions. |
| CVE-2026-97301 | CVE-2026-97301 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions. |
| CVE-2026-97300 | CVE-2026-97300 CVSS 6.5 | Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. |
| CVE-2026-9730 | CVE-2026-9730 CVSS 4.3 | The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to mi… |
| CVE-2026-97299 | CVE-2026-97299 CVSS 5.4 | Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. |
| CVE-2026-97298 | CVE-2026-97298 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions. |
| CVE-2026-97297 | CVE-2026-97297 CVSS 7.6 | Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions. |
| CVE-2026-97293 | CVE-2026-97293 CVSS 8.5 | Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions. |
| CVE-2026-97292 | CVE-2026-97292 CVSS 6.5 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. |
| CVE-2026-97291 | CVE-2026-97291 CVSS 8.8 | Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. |
| CVE-2026-97290 | CVE-2026-97290 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. |
| CVE-2026-9729 | CVE-2026-9729 CVSS 6.4 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notificat… |
| CVE-2026-97289 | CVE-2026-97289 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions. |
| CVE-2026-97288 | CVE-2026-97288 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. |
| CVE-2026-97287 | CVE-2026-97287 CVSS 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows… |
| CVE-2026-97286 | CVE-2026-97286 CVSS 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows S… |
| CVE-2026-97285 | CVE-2026-97285 CVSS 5.4 | Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. |
| CVE-2026-97284 | CVE-2026-97284 CVSS 8.8 | Contributor PHP Object Injection in Icegram <= 3.1.31 versions. |
| CVE-2026-97283 | CVE-2026-97283 CVSS 9.8 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affect… |
| CVE-2026-97282 | CVE-2026-97282 CVSS 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. |
| CVE-2026-97281 | CVE-2026-97281 CVSS 6.3 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. |
| CVE-2026-97280 | CVE-2026-97280 CVSS 6.5 | Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. Thi… |
| CVE-2026-9728 | CVE-2026-9728 CVSS 6.4 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out … |
| CVE-2026-97279 | CVE-2026-97279 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. |
| CVE-2026-97277 | CVE-2026-97277 CVSS 7.6 | Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. |
| CVE-2026-97276 | CVE-2026-97276 CVSS 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected X… |
| CVE-2026-97275 | CVE-2026-97275 CVSS 5.3 | Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-build… |
| CVE-2026-97274 | CVE-2026-97274 CVSS 9.8 | Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. |
| CVE-2026-97273 | CVE-2026-97273 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. |
| CVE-2026-97272 | CVE-2026-97272 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. |
| CVE-2026-97271 | CVE-2026-97271 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. |
| CVE-2026-97270 | CVE-2026-97270 CVSS 6.5 | Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions. |
| CVE-2026-97269 | CVE-2026-97269 CVSS 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions. |
| CVE-2026-97268 | CVE-2026-97268 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. |
| CVE-2026-97267 | CVE-2026-97267 CVSS 4.3 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. |
| CVE-2026-97266 | CVE-2026-97266 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions. |
| CVE-2026-97265 | CVE-2026-97265 CVSS 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. T… |
| CVE-2026-97262 | CVE-2026-97262 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. |
| CVE-2026-97261 | CVE-2026-97261 CVSS 5.3 | Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions. |
| CVE-2026-97260 | CVE-2026-97260 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions. |
| CVE-2026-9726 | CVE-2026-9726 CVSS 9.8alternativecommerce | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Inject… |
| CVE-2026-97259 | CVE-2026-97259 | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access … |
| CVE-2026-97258 | CVE-2026-97258 CVSS 6.5 | Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions. |
| CVE-2026-97257 | CVE-2026-97257 CVSS 8.8 | Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Even… |
| CVE-2026-97256 | CVE-2026-97256 CVSS 7.2 | Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. |