Export limit exceeded: 14427 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (14427 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65441 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | ||||
| CVE-2026-59558 | 2 Wordpress, Wpdevelop | 2 Wordpress, Booking Calendar | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | ||||
| CVE-2026-65436 | 2 Themeum, Wordpress | 2 Kirki, Wordpress | 2026-07-28 | 6.8 Medium |
| Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions. | ||||
| CVE-2026-65439 | 2 Themefic, Wordpress | 2 Ultimate Addons For Contact Form 7, Wordpress | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | ||||
| CVE-2026-65446 | 2 Wordpress, Wp Chill | 2 Wordpress, Kali Forms | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | ||||
| CVE-2026-49779 | 2 Addify, Wordpress | 2 Tax Exempt For Woocommerce, Wordpress | 2026-07-28 | 6.5 Medium |
| Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5. | ||||
| CVE-2026-65438 | 2 Kofimokome, Wordpress | 2 Message Filter For Contact Form 7, Wordpress | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | ||||
| CVE-2026-65440 | 2 Roxnor, Wordpress | 2 Getgenie, Wordpress | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | ||||
| CVE-2026-65447 | 2 Wasiliy Strecker / Contestgallery Developer, Wordpress | 2 Contest Gallery, Wordpress | 2026-07-28 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | ||||
| CVE-2026-11962 | 2 Fileorganizer, Wordpress | 2 Fileorganizer, Wordpress | 2026-07-28 | 8.8 High |
| The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code execution. This is an incomplete fix of CVE-2024-7985, which only added file-type validation to the upload operation. | ||||
| CVE-2026-12277 | 2 Frontend File Manager Plugin, Wordpress | 2 Frontend File Manager Plugin, Wordpress | 2026-07-28 | 8.7 High |
| The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover. | ||||
| CVE-2026-47100 | 2 Funnelkit, Wordpress | 3 Funnel Builder, Funnel Builder For Woocommerce Checkout, Wordpress | 2026-07-28 | 7.5 High |
| Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors. | ||||
| CVE-2022-50960 | 3 Icu-project, Varun Sridharan, Wordpress | 3 International Components For Unicode, International Sms For Contact Form, Wordpress | 2026-07-28 | 6.1 Medium |
| WordPress International SMS for Contact Form 7 Integration version 1.2 contains a reflected cross-site scripting vulnerability in the page parameter of the admin settings interface. Attackers can inject malicious scripts through the page parameter in class-sms-log-display.php to execute arbitrary JavaScript in administrator browsers. | ||||
| CVE-2022-50949 | 3 A-j-evolution, Cs-technologies, Wordpress | 3 Videos Sync Pdf, Evolution, Wordpress | 2026-07-28 | 6.4 Medium |
| WordPress Plugin Videos sync PDF 1.7.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by exploiting unsanitized mov, pdf, mp4, webm, and ogg parameters. Attackers can inject payloads like autofocus onfocus event handlers through the plugin options panel to execute arbitrary JavaScript when administrators view or edit video settings. | ||||
| CVE-2022-50797 | 3 Halfdata, Ithemes, Wordpress | 3 Stripe Green Downloads, Stripe, Wordpress | 2026-07-28 | 6.4 Medium |
| Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module manipulation. | ||||
| CVE-2021-47983 | 3 Checkoutplugins, Mra13, Wordpress | 3 Stripe Payments For Woocommerce, Accept Stripe Payments, Wordpress | 2026-07-28 | 6.4 Medium |
| WordPress Plugin Stripe Payments 2.0.39 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the currency_code field to execute arbitrary JavaScript in administrator browsers when settings are viewed. | ||||
| CVE-2021-47977 | 3 Gotmls, Ithemes, Wordpress | 3 Malware Security And Bruteforce Firewall, Security, Wordpress | 2026-07-28 | 7.5 High |
| WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with path traversal sequences to access sensitive system files outside the intended directory. | ||||
| CVE-2021-47948 | 3 Ayecode, Invoicing, Wordpress | 3 Getpaid, Payments Plugin Getpaid, Wordpress | 2026-07-28 | 5.4 Medium |
| WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject arbitrary HTML code by exploiting the Help Text field in payment forms. Attackers can inject malicious HTML including image tags and scripts into the Help Text field during payment form creation, which gets stored in the database and executed in the browser when the form is viewed. | ||||
| CVE-2021-47929 | 3 Bestwebsoft, Filterable-portfolio, Wordpress | 3 Portfolio, Filterable Portfolio Gallery, Wordpress | 2026-07-28 | 6.4 Medium |
| Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed, affecting all users viewing the page. | ||||
| CVE-2021-47922 | 2 Soliloquywp, Wordpress | 3 Slider, Slider By Soliloquy, Wordpress | 2026-07-28 | 6.4 Medium |
| Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the title parameter. Attackers can add JavaScript payloads in the title field when creating or editing sliders, which executes in the browsers of users viewing the slider on both administrative and frontend pages. | ||||