Search

Search Results (399351 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-81156 2026-10-11 6.8 Medium
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its gallery settings before outputting them on the gallery edit screen, allowing users with the Contributor role and above to store JavaScript that executes in the context of an administrator who opens the gallery for editing.
CVE-2026-81155 2026-10-11 6.8 Medium
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape a gallery setting before outputting it on a frontend page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing a gallery, including administrators.
CVE-2026-81154 2026-10-11 6.8 Medium
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape image alt text before outputting it in one of its gallery layouts, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any user viewing the affected gallery, including administrators.
CVE-2026-81153 2026-10-11 6.8 Medium
The Robo Gallery WordPress plugin before 5.2.6 does not sanitise and escape some of its image settings before outputting them in a gallery page, allowing users with the Author role and above to perform Stored Cross-Site Scripting attacks that execute in the browser of any visitor viewing the gallery, including administrators, even where the unfiltered_html capability is disallowed such as on multisite.
CVE-2026-78535 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
CVE-2026-78534 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Educavo <= 3.4.2 versions.
CVE-2026-78533 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
CVE-2026-78532 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in LMS <= 8.3 versions.
CVE-2026-78531 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Jacqueline <= 2.22 versions.
CVE-2026-78529 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
CVE-2026-66569 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
CVE-2026-66568 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
CVE-2026-66567 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
CVE-2026-66566 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
CVE-2026-66565 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in FC United <= 1.1.1 versions.
CVE-2026-66564 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in ShiftCV <= 3.0.14 versions.
CVE-2026-66563 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Windsor <= 2.10 versions.
CVE-2026-66483 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Education Center <= 3.6.12 versions.
CVE-2026-66482 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Drone Media <= 2.2.0 versions.
CVE-2026-62125 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Asia Garden <= 1.3.1 versions.