Export limit exceeded: 21172 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404419 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-91829 | 2026-10-11 | 7.1 High | ||
| The Subscribe to Comments WordPress plugin before 2.3.3 does not properly validate a parameter before reflecting it into a link target, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting via a crafted URL against anyone who clicks it, including administrators. | ||||
| CVE-2026-89305 | 2026-10-11 | 6.5 Medium | ||
| The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks. | ||||
| CVE-2026-89304 | 2026-10-11 | 6.5 Medium | ||
| The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform blind SQL injection attacks. | ||||
| CVE-2026-89302 | 2026-10-11 | 8.6 High | ||
| The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-89299 | 2026-10-11 | 8.6 High | ||
| The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-89297 | 2026-10-11 | 8.6 High | ||
| The Loja Automática WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-89287 | 2026-10-11 | 8.6 High | ||
| The ASPL Product Quotation WordPress plugin through 1.1.0 does not sanitize and escape a parameter before using it in SQL statements, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database. | ||||
| CVE-2026-89285 | 2026-10-11 | 8.6 High | ||
| The Datalist it WordPress plugin through 0.0.3 does not sanitize and escape several request parameters before using them to build a SQL query, allowing unauthenticated attackers to perform SQL injection and read arbitrary data from the database. | ||||
| CVE-2026-89283 | 2026-10-11 | 8.6 High | ||
| The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password. | ||||
| CVE-2026-89234 | 2026-10-11 | 8.6 High | ||
| The WP-Partner WordPress plugin through 1.2.1 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. | ||||
| CVE-2026-89232 | 2026-10-11 | 8.6 High | ||
| The Recordbrowser WordPress plugin through 1.1.7 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. | ||||
| CVE-2026-89214 | 2026-10-11 | 8.6 High | ||
| The WpCues Basic Quiz WordPress plugin through 1.6.5 does not properly sanitise and escape values before using them in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. | ||||
| CVE-2026-89213 | 2026-10-11 | 8.6 High | ||
| The Llavero.io WordPress plugin through 0.1.4 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. | ||||
| CVE-2026-89195 | 2026-10-11 | 8.6 High | ||
| The Site Setup Wizard WordPress plugin through 1.5.8 does not properly sanitise and escape a parameter before using it in a SQL statement, which allows unauthenticated attackers to perform SQL injection attacks and read data from the database. | ||||
| CVE-2026-88930 | 2026-10-11 | 8.6 High | ||
| The Social Web Suite WordPress plugin through 4.1.12 does not require its shared secret to be set before accepting requests authorised by it, and does not sanitise and escape a parameter before using it in an SQL statement, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-88905 | 2026-10-11 | 8.8 High | ||
| The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output. | ||||
| CVE-2026-88903 | 2026-10-11 | 8.8 High | ||
| The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated attackers to publish arbitrary posts containing malicious JavaScript on any site where its API key has never been configured. | ||||
| CVE-2026-88827 | 2026-10-11 | 8.8 High | ||
| The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges. | ||||
| CVE-2026-88826 | 2026-10-11 | 8.8 High | ||
| The SmugMug Embed WordPress plugin through 3.13 does not have authorisation or CSRF checks on an AJAX action that stores gallery data, and does not sanitise or escape that data before outputting it, allowing unauthenticated users to store arbitrary web scripts that execute when an administrator views the SmugMug Embed WordPress plugin through 3.13's settings screen. | ||||
| CVE-2026-88785 | 2026-10-11 | 4.7 Medium | ||
| The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them. | ||||