Export limit exceeded: 404440 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404440 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-42709 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Food Menu – Restaurant Menu & Online Ordering for WooCommerce <= 6.0.5 versions.
CVE-2026-42704 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in Kids Care <= 3.2.4 versions.
CVE-2026-42702 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Tutor LMS <= 4.1.0 versions.
CVE-2026-42699 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
CVE-2026-42697 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions.
CVE-2026-42695 2026-10-11 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Flowplayer Video Player fv-wordpress-flowplayer allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.54.7212.
CVE-2026-42693 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions.
CVE-2026-42633 2026-10-11 8.5 High
Subscriber SQL Injection in Events Manager <= 7.4.6 versions.
CVE-2026-42632 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Qode Real Estate <= 1.1.7.3 versions.
CVE-2026-42631 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions.
CVE-2026-42630 2026-10-11 7.5 High
Unauthenticated Sensitive Data Exposure in Web Plura Backup &amp; Restore Manager <= 0.2.25 versions.
CVE-2026-42419 2026-10-11 5.9 Medium
Unauthenticated Sensitive Data Exposure in Swish Migrate and Backup <= 1.4.0 versions.
CVE-2026-40803 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Jotform &#8211; AI Chatbot <= 3.8.2 versions.
CVE-2026-40800 2026-10-11 9.3 Critical
Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions.
CVE-2026-39800 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce <= 1.24 versions.
CVE-2026-39799 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP File Download <= 6.3.6 versions.
CVE-2026-27350 1 Builderius.io 1 Builderius 2026-10-11 7.2 High
Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery. This issue affects Builderius: from 1.4 through 1.4-beta.
CVE-2026-12980 2026-10-11 6.8 Medium
The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed.
CVE-2026-107694 2026-10-11 2.7 Low
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors.
CVE-2026-105889 2026-10-11 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.