Export limit exceeded: 403868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (403868 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103424 | 2026-10-10 | 5.4 Medium | ||
| The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment from the attacker's email address has been approved; on default WordPress installations, only the first comment from a given email address is held for moderation, meaning subsequent comments auto-approve and immediately expose the payload to site visitors. | ||||
| CVE-2026-6723 | 2026-10-10 | 5.3 Medium | ||
| The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confirmation, reassigning the appointment to another user, and changing the service type. | ||||
| CVE-2026-104735 | 2026-10-10 | 6.4 Medium | ||
| The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is not neutralized at save time because post_content stores only a benign block reference to an external feed URL; the malicious HTML is injected at render time from the attacker-controlled RSS feed title, bypassing any save-time wp_kses filtering. | ||||
| CVE-2026-103964 | 2026-10-10 | 4.3 Medium | ||
| The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session hijack and account takeover. Exploitation requires an administrator to perform the Suspend action against the attacker's account, which causes the plugin to synchronously compile and send the suspension email inside the administrator's authenticated HTTP request — making the administrator's session cookies available to the template engine at send time. | ||||
| CVE-2026-87869 | 2026-10-10 | 6.1 Medium | ||
| The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build_query() — a WordPress core function that does NOT re-encode values ($urlencode=false). The resulting URL, containing unescaped special characters, is injected into a data-next-page HTML attribute via preg_replace() without esc_attr() or esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link. | ||||
| CVE-2026-97630 | 2026-10-10 | 6.4 Medium | ||
| The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the profile_videos_enable_bio option to be enabled, as script execution occurs on the author bio/archive page where the profile-video shortcode is rendered. | ||||
| CVE-2026-5727 | 2026-10-10 | 5.4 Medium | ||
| The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish their own Hello+ header/footer templates and draft currently active templates owned by higher-privileged users. | ||||
| CVE-2026-102401 | 2026-10-10 | 6.4 Medium | ||
| The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload only fires for logged-out site visitors, as the vulnerable login-form.php template branch is gated on !is_user_logged_in(); authenticated users viewing the same page are served a different template and are not affected. | ||||
| CVE-2026-101324 | 2026-10-10 | 4.7 Medium | ||
| The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires a site administrator to have configured a Custom HTML field on a published form containing a {get.*} SmartCode inside a URL-accepting attribute such as iframe src or a href — a documented Fluent Forms feature. | ||||
| CVE-2026-103889 | 2026-10-10 | 9.8 Critical | ||
| The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthenticated attackers to execute code on the server. The only nonce and authentication check in the handler is entirely enclosed in a block comment with no replacement, making the endpoint reachable via a single unauthenticated POST to any URL on the site. | ||||
| CVE-2026-104993 | 2026-10-10 | 6.4 Medium | ||
| The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator has added and configured the Contact Email custom field to render on the public single-listing output page, and that the administrator subsequently approves the attacker's submitted listing. | ||||
| CVE-2026-96648 | 2026-10-10 | 6.4 Medium | ||
| The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable by Subscriber-level users when an administrator has added their role to the plugin's 'access_roles' setting, which is a documented and explicitly supported plugin feature that grants lower-privileged users access to the dtgs_nonce required to reach the vulnerable updateRows action handler. | ||||
| CVE-2026-93017 | 1 Redhat | 2 Openshift, Openshift Container Platform | 2026-10-10 | 7.7 High |
| The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: https://github.com/openshift/insights-operator/blob/8f15e3157ff09f54ab22801f5b21da35a195cc6d/manifests/03-clusterrole.yaml#L368-L373 ``` - apiGroups: - "" resources: - secrets verbs: - get - list ``` By spawning a pod with the gather service account mounted, an attacker will be able to access any secret in any namespace. ``` spec: serviceAccountName:"gather" ``` | ||||
| CVE-2026-84875 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 7.5 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84249 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 9.8 Critical |
| IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function. | ||||
| CVE-2026-84245 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 7.8 High |
| IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this vulnerability to gain root privileges and access or modify sensitive system files. | ||||
| CVE-2026-84198 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow. | ||||
| CVE-2026-84057 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 8.1 High |
| IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-84035 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 8.1 High |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. | ||||
| CVE-2026-80381 | 1 Ibm | 1 Guardium Data Protection | 2026-10-10 | 9.8 Critical |
| IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection. | ||||