Search Results (44806 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-28004 2 Strategy11team, Wordpress 2 Business Directory Plugin, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
CVE-2026-61965 2 Ahmad, Wordpress 2 Geekybot, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
CVE-2026-66429 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66456 2 Bestwebsoft, Wordpress 2 Profile Extra Fields, Wordpress 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
CVE-2026-66467 2 Wordpress, Wpmanageninja 2 Wordpress, Fluentcommunity 2026-08-14 6.5 Medium
Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.
CVE-2026-73340 2 Fifu, Wordpress 2 Featured Image From Url, Wordpress 2026-08-14 6.5 Medium
Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
CVE-2026-65480 2 Codexthemes, Wordpress 2 Thegem, Wordpress 2026-08-14 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1.
CVE-2026-28003 2 Wordpress, Yonifre 2 Wordpress, Maspik – Spam Blacklist 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
CVE-2026-28158 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
CVE-2026-65580 2 Bracketweb, Wordpress 2 Agrion, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
CVE-2026-66468 2 Powerfulwp, Wordpress 2 Local Delivery Drivers For Woocommerce, Wordpress 2026-08-14 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
CVE-2026-68419 1 Linux 1 Linux Kernel 2026-08-13 7.8 High
In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a two step process is used where the buffer is allocated in userspace and explicitly registered with the normal reg_mr mechanism prior to creating the actual QP/CQ/SRQ object. These special registrations are indicated via an ABI field so the driver knows that they do not have a valid mkey and to skip the actual CQP command submission. Since these are real MR objects from the core's perspective, it is possible for a user application to invoke rereg_mr on them and cause a real CQP op to be emitted with the zero-initialized mkey value of 0. Fix this by preventing rereg_mr on these special regions.
CVE-2026-27539 2 Welcart, Wordpress 2 Welcart E-commerce, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
CVE-2026-66471 2 Themepoints, Wordpress 2 Accordion, Wordpress 2026-08-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
CVE-2026-66697 2 Colissimo, Wordpress 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-3639 2 Buildwps, Wordpress 2 Ppwp – Password Protect Pages, Wordpress 2026-08-13 6.4 Medium
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-28182 2 Acymailing Newsletter Team, Wordpress 2 Acymailing Smtp Newsletter, Wordpress 2026-08-13 6.5 Medium
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
CVE-2026-28187 2 Echoplugins, Wordpress 2 Knowledge Base For Documentation, Faqs With Ai Assistance, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions.
CVE-2026-73344 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-08-13 5.9 Medium
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-66698 2 Brainstorm Force, Wordpress 2 Suredash, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.