87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,001–1,050 of 87,929 · page 21 of 1759

IDTitleSummary
CVE-2026-97308CVE-2026-97308
CVSS 4.8
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
CVE-2026-97307CVE-2026-97307
CVSS 7.5
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sens…
CVE-2026-97305CVE-2026-97305Authorization Bypass Through User-Controlled Key vulnerability in Themeisle AI Chatbot for WordPress – Hyve Lite hyve-lite allows Exploiting Incorrectly Config…
CVE-2026-97304CVE-2026-97304
CVSS 6.5
Missing Authorization vulnerability in Arraytics Timetics timetics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects T…
CVE-2026-97303CVE-2026-97303
CVSS 7.6
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly…
CVE-2026-97302CVE-2026-97302
CVSS 5.3
Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
CVE-2026-97301CVE-2026-97301
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
CVE-2026-97300CVE-2026-97300
CVSS 6.5
Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions.
CVE-2026-9730CVE-2026-9730
CVSS 4.3
The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to mi…
CVE-2026-97299CVE-2026-97299
CVSS 5.4
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
CVE-2026-97298CVE-2026-97298
CVSS 6.5
Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
CVE-2026-97297CVE-2026-97297
CVSS 7.6
Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.
CVE-2026-97293CVE-2026-97293
CVSS 8.5
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
CVE-2026-97292CVE-2026-97292
CVSS 6.5
Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
CVE-2026-97291CVE-2026-97291
CVSS 8.8
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
CVE-2026-97290CVE-2026-97290
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
CVE-2026-9729CVE-2026-9729
CVSS 6.4
The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notificat…
CVE-2026-97289CVE-2026-97289
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
CVE-2026-97288CVE-2026-97288
CVSS 6.5
Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
CVE-2026-97287CVE-2026-97287
CVSS 8.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows…
CVE-2026-97286CVE-2026-97286
CVSS 6.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows S…
CVE-2026-97285CVE-2026-97285
CVSS 5.4
Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.
CVE-2026-97284CVE-2026-97284
CVSS 8.8
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
CVE-2026-97283CVE-2026-97283
CVSS 9.8
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affect…
CVE-2026-97282CVE-2026-97282
CVSS 5.3
Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
CVE-2026-97281CVE-2026-97281
CVSS 6.3
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
CVE-2026-97280CVE-2026-97280
CVSS 6.5
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. Thi…
CVE-2026-9728CVE-2026-9728
CVSS 6.4
The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out …
CVE-2026-97279CVE-2026-97279
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions.
CVE-2026-97277CVE-2026-97277
CVSS 7.6
Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.
CVE-2026-97276CVE-2026-97276
CVSS 7.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected X…
CVE-2026-97275CVE-2026-97275
CVSS 5.3
Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-build…
CVE-2026-97274CVE-2026-97274
CVSS 9.8
Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.
CVE-2026-97273CVE-2026-97273
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
CVE-2026-97272CVE-2026-97272
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.
CVE-2026-97271CVE-2026-97271
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-97270CVE-2026-97270
CVSS 6.5
Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions.
CVE-2026-97269CVE-2026-97269
CVSS 6.5
Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.
CVE-2026-97268CVE-2026-97268
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
CVE-2026-97267CVE-2026-97267
CVSS 4.3
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
CVE-2026-97266CVE-2026-97266
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.
CVE-2026-97265CVE-2026-97265
CVSS 6.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. T…
CVE-2026-97262CVE-2026-97262
CVSS 6.5
Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.
CVE-2026-97261CVE-2026-97261
CVSS 5.3
Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.
CVE-2026-97260CVE-2026-97260
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
CVE-2026-9726CVE-2026-9726
CVSS 9.8alternativecommerce
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Inject…
CVE-2026-97259CVE-2026-97259Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access …
CVE-2026-97258CVE-2026-97258
CVSS 6.5
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
CVE-2026-97257CVE-2026-97257
CVSS 8.8
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Even…
CVE-2026-97256CVE-2026-97256
CVSS 7.2
Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.