Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-47982 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2021-47982)
cross-site scripting in wordpress (CVE-2021-47982). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-50953 |
|
Path Traversal in wordpress (CVE-2022-50953)
path traversal in wordpress (CVE-2022-50953). Confidential information can be exposed externally.
|
| CVE-2026-11471 |
|
Vulnerability in sqli (CVE-2026-11471)
vulnerability in sqli (CVE-2026-11471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11472 |
|
Vulnerability in sqli (CVE-2026-11472)
vulnerability in sqli (CVE-2026-11472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11473 |
|
Vulnerability in sqli (CVE-2026-11473)
vulnerability in sqli (CVE-2026-11473). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11470 |
|
Path Traversal in org.hswebframework.web:hsweb-system-file (CVE-2026-11470)
path traversal in org.hswebframework.web:hsweb-system-file (CVE-2026-11470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11468 |
|
Cross-Site Scripting (XSS) in CVE-2026-11468 (CVE-2026-11468)
cross-site scripting in CVE-2026-11468 (CVE-2026-11468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11467 |
|
Path Traversal in path-traversal (CVE-2026-11467)
path traversal in path-traversal (CVE-2026-11467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11462 |
|
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
|
| CVE-2026-11463 |
|
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
|
| CVE-2026-11456 |
|
Vulnerability in sqli (CVE-2026-11456)
vulnerability in sqli (CVE-2026-11456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11453 |
|
Vulnerability in sqli (CVE-2026-11453)
vulnerability in sqli (CVE-2026-11453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26422 |
|
Vulnerability in privilege-escalation (CVE-2026-26422)
vulnerability in privilege-escalation (CVE-2026-26422). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11436 |
|
Cross-Site Scripting (XSS) in CVE-2026-11436 (CVE-2026-11436)
cross-site scripting in CVE-2026-11436 (CVE-2026-11436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11435 |
|
Vulnerability in sqli (CVE-2026-11435)
vulnerability in sqli (CVE-2026-11435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11434 |
|
Cross-Site Scripting (XSS) in CVE-2026-11434 (CVE-2026-11434)
cross-site scripting in CVE-2026-11434 (CVE-2026-11434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11412 |
|
Vulnerability in sqli (CVE-2026-11412)
vulnerability in sqli (CVE-2026-11412). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11411 |
|
Path Traversal in path-traversal (CVE-2026-11411)
path traversal in path-traversal (CVE-2026-11411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9829 |
|
SQL Injection in wordpress (CVE-2026-9829)
SQL injection in wordpress (CVE-2026-9829). Confidential information can be exposed externally.
|
| CVE-2026-9594 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9594)
cross-site scripting in wordpress (CVE-2026-9594). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9851 |
|
Vulnerability in wordpress (CVE-2026-9851)
vulnerability in wordpress (CVE-2026-9851). Successful exploitation can lead to full system takeover.
|
| CVE-2025-2414 |
|
Vulnerability in CVE-2025-2414 (CVE-2025-2414)
vulnerability in CVE-2025-2414 (CVE-2025-2414). Confidential information can be exposed externally.
|
| CVE-2025-2415 |
|
Vulnerability in CVE-2025-2415 (CVE-2025-2415)
vulnerability in CVE-2025-2415 (CVE-2025-2415). Confidential information can be exposed externally.
|
| CVE-2026-8978 |
|
SQL Injection in wordpress (CVE-2026-8978)
SQL injection in wordpress (CVE-2026-8978). Confidential information can be exposed externally.
|
| CVE-2026-7796 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7796)
cross-site scripting in wordpress (CVE-2026-7796). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8991 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8991)
cross-site scripting in wordpress (CVE-2026-8991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9280 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9280)
cross-site scripting in wordpress (CVE-2026-9280). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9197 |
|
Path Traversal in wordpress (CVE-2026-9197)
path traversal in wordpress (CVE-2026-9197). Confidential information can be exposed externally.
|
| CVE-2026-7795 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7795)
cross-site scripting in wordpress (CVE-2026-7795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7566 |
|
Unsafe Deserialization in wordpress (CVE-2026-7566)
vulnerability in wordpress (CVE-2026-7566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7565 |
|
Path Traversal in wordpress (CVE-2026-7565)
path traversal in wordpress (CVE-2026-7565). Confidential information can be exposed externally.
|
| CVE-2026-7537 |
|
Unrestricted File Upload in wordpress (CVE-2026-7537)
vulnerability in wordpress (CVE-2026-7537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2500 |
|
Path Traversal in csharp (CVE-2026-2500)
path traversal in csharp (CVE-2026-2500). Confidential information can be exposed externally. Exploitable via ``filename``.
|
| CVE-2026-8901 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8901)
cross-site scripting in wordpress (CVE-2026-8901). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9281 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9281)
cross-site scripting in wordpress (CVE-2026-9281). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8438 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8438)
cross-site scripting in wordpress (CVE-2026-8438). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8900 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8900)
cross-site scripting in wordpress (CVE-2026-8900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6448 |
|
SQL Injection in wordpress (CVE-2026-6448)
SQL injection in wordpress (CVE-2026-6448). Confidential information can be exposed externally.
|
| CVE-2026-8893 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8893)
cross-site scripting in wordpress (CVE-2026-8893). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6240 |
|
Vulnerability in dos (CVE-2026-6240)
vulnerability in dos (CVE-2026-6240). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6241 |
|
Vulnerability in dos (CVE-2026-6241)
vulnerability in dos (CVE-2026-6241). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6239 |
|
Vulnerability in dos (CVE-2026-6239)
vulnerability in dos (CVE-2026-6239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7654 |
|
Unsafe Deserialization in wordpress (CVE-2026-7654)
vulnerability in wordpress (CVE-2026-7654). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
|
| CVE-2026-11429 |
|
Path Traversal in path-traversal (CVE-2026-11429)
path traversal in path-traversal (CVE-2026-11429). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|
| CVE-2026-11424 |
|
Information Disclosure in ssrf (CVE-2026-11424)
vulnerability in ssrf (CVE-2026-11424). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|
| CVE-2026-11416 |
|
Path Traversal in path-traversal (CVE-2026-11416)
path traversal in path-traversal (CVE-2026-11416). Data can be tampered with by attackers.
|
| CVE-2026-11431 |
|
Path Traversal in path-traversal (CVE-2026-11431)
path traversal in path-traversal (CVE-2026-11431). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|
| CVE-2026-11423 |
|
Path Traversal in path-traversal (CVE-2026-11423)
path traversal in path-traversal (CVE-2026-11423). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36785 |
|
Vulnerability in dos (CVE-2026-36785)
vulnerability in dos (CVE-2026-36785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47743 |
|
Cross-Site Scripting (XSS) in shopper/framework (CVE-2026-47743)
cross-site scripting in shopper/framework (CVE-2026-47743). Confidential information can be exposed externally. Exploitable via ``Hidden``. Mitigation: upgrade to `2.8.0` or later.
|