脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-66694 |
|
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
|
| CVE-2026-66664 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
|
| CVE-2026-66663 |
|
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
|
| CVE-2026-66457 |
|
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
|
| CVE-2026-66440 |
|
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
|
| CVE-2026-66439 |
|
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
|
| CVE-2026-65569 |
|
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
|
| CVE-2026-65560 |
|
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
|
| CVE-2026-65565 |
|
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
|
| CVE-2026-65559 |
|
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
|
| CVE-2026-65544 |
|
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
|
| CVE-2026-65545 |
|
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
|
| CVE-2026-65547 |
|
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
|
| CVE-2026-65517 |
|
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
|
| CVE-2026-65515 |
|
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
|
| CVE-2026-65513 |
|
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
|
| CVE-2026-65509 |
|
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
|
| CVE-2026-61964 |
|
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
|
| CVE-2026-61963 |
|
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
|
| CVE-2026-61982 |
|
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
|
| CVE-2026-61961 |
|
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
|
| CVE-2026-28183 |
|
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
|
| CVE-2026-28172 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
|
| CVE-2026-28177 |
|
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
|
| CVE-2026-28143 |
|
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
|
| CVE-2026-28141 |
|
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
|
| CVE-2026-28111 |
|
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
|
| CVE-2026-28082 |
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
|
| CVE-2025-15028 |
|
wordpress に クロスサイトスクリプティング (CVE-2025-15028)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2025-15028) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-54225 |
|
apache の脆弱性 (CVE-2026-54225)
apache に 脆弱性 (CVE-2026-54225) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-57819 |
|
apache の脆弱性 (CVE-2026-57819)
apache に 脆弱性 (CVE-2026-57819) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-64958 |
|
apache の脆弱性 (CVE-2026-64958)
apache に 脆弱性 (CVE-2026-64958) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-19021 |
|
sqli の脆弱性 (CVE-2026-19021)
sqli に 脆弱性 (CVE-2026-19021) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-18649 |
|
dos の脆弱性 (CVE-2026-18649)
dos に 脆弱性 (CVE-2026-18649) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-18597 |
|
ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-18597)
ssrf に SSRF (CVE-2026-18597) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-18510 |
|
wordpress に クロスサイトスクリプティング (CVE-2026-18510)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-18510) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-15459 |
|
wordpress に 認証バイパス (CVE-2026-15459)
wordpress に 認証バイパス (CVE-2026-15459) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-18325 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-16636 |
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
| CVE-2026-15991 |
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
| CVE-2026-18991 |
|
path-traversal に パストラバーサル (CVE-2026-18991)
path-traversal に パストラバーサル (CVE-2026-18991) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67872 |
|
dos の脆弱性 (CVE-2026-67872)
dos に 脆弱性 (CVE-2026-67872) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67871 |
|
c の脆弱性 (CVE-2026-67871)
c に 脆弱性 (CVE-2026-67871) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67869 |
|
dos の脆弱性 (CVE-2026-67869)
dos に 脆弱性 (CVE-2026-67869) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-18970 |
|
sqli の脆弱性 (CVE-2026-18970)
sqli に 脆弱性 (CVE-2026-18970) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67867 |
|
dos の脆弱性 (CVE-2026-67867)
dos に 脆弱性 (CVE-2026-67867) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67863 |
|
dos に 解放後使用 (Use-After-Free) (CVE-2026-67863)
dos に 脆弱性 (CVE-2026-67863) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67866 |
|
dos の脆弱性 (CVE-2026-67866)
dos に 脆弱性 (CVE-2026-67866) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67865 |
|
dos に 境界外読み取り (CVE-2026-67865)
dos に 脆弱性 (CVE-2026-67865) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67864 |
|
dos の脆弱性 (CVE-2026-67864)
dos に 脆弱性 (CVE-2026-67864) が存在。不正な操作・情報露出のリスクがあります。
|