Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16573 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16573)
cross-site scripting in wordpress (CVE-2026-16573). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16561 |
|
Vulnerability in wordpress (CVE-2026-16561)
vulnerability in wordpress (CVE-2026-16561). Confidential information can be exposed externally.
|
| CVE-2026-16055 |
|
Authentication Bypass in wordpress (CVE-2026-16055)
authentication bypass in wordpress (CVE-2026-16055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16036 |
|
Authentication Bypass in wordpress (CVE-2026-16036)
authentication bypass in wordpress (CVE-2026-16036). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15372 |
|
Authentication Bypass in wordpress (CVE-2026-15372)
authentication bypass in wordpress (CVE-2026-15372). Confidential information can be exposed externally.
|
| CVE-2026-15360 |
|
SQL Injection in wordpress (CVE-2026-15360)
SQL injection in wordpress (CVE-2026-15360). Confidential information can be exposed externally.
|
| CVE-2026-15230 |
|
Vulnerability in wordpress (CVE-2026-15230)
vulnerability in wordpress (CVE-2026-15230). Confidential information can be exposed externally.
|
| CVE-2026-15210 |
|
Authentication Bypass in wordpress (CVE-2026-15210)
authentication bypass in wordpress (CVE-2026-15210). Confidential information can be exposed externally.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2025-15677 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15677)
cross-site scripting in wordpress (CVE-2025-15677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8790 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8790)
cross-site scripting in wordpress (CVE-2026-8790). Risk of unauthorized operations or information disclosure. Exploitable via ``shouttext``.
|
| CVE-2026-9273 |
|
Vulnerability in wordpress (CVE-2026-9273)
vulnerability in wordpress (CVE-2026-9273). Confidential information can be exposed externally.
|
| CVE-2026-7753 |
|
Vulnerability in wordpress (CVE-2026-7753)
vulnerability in wordpress (CVE-2026-7753). Confidential information can be exposed externally. Exploitable via ``ccb_export_nonce``.
|
| CVE-2026-8761 |
|
Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
|
| CVE-2026-5062 |
|
SQL Injection in wordpress (CVE-2026-5062)
SQL injection in wordpress (CVE-2026-5062). Confidential information can be exposed externally.
|
| CVE-2026-15918 |
|
SQL Injection in wordpress (CVE-2026-15918)
SQL injection in wordpress (CVE-2026-15918). Confidential information can be exposed externally.
|
| CVE-2026-11421 |
|
SQL Injection in wordpress (CVE-2026-11421)
SQL injection in wordpress (CVE-2026-11421). Confidential information can be exposed externally.
|
| CVE-2026-15941 |
|
SQL Injection in wordpress (CVE-2026-15941)
SQL injection in wordpress (CVE-2026-15941). Confidential information can be exposed externally. Exploitable via ``edit_posts``.
|
| CVE-2026-18322 |
|
Privilege Escalation in wordpress (CVE-2026-18322)
vulnerability in wordpress (CVE-2026-18322). Successful exploitation can lead to full system takeover. Exploitable via ``save``.
|
| CVE-2026-16143 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16143)
cross-site scripting in wordpress (CVE-2026-16143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16623 |
|
Code Injection in wordpress (CVE-2026-16623)
code injection in wordpress (CVE-2026-16623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16618 |
|
Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16548 |
|
Unrestricted File Upload in wordpress (CVE-2026-16548)
vulnerability in wordpress (CVE-2026-16548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16547 |
|
Vulnerability in wordpress (CVE-2026-16547)
vulnerability in wordpress (CVE-2026-16547). Confidential information can be exposed externally.
|
| CVE-2026-16546 |
|
Vulnerability in wordpress (CVE-2026-16546)
vulnerability in wordpress (CVE-2026-16546). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16536 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16536)
SSRF in wordpress (CVE-2026-16536). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16296 |
|
Open Redirect in wordpress (CVE-2026-16296)
vulnerability in wordpress (CVE-2026-16296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16295 |
|
Vulnerability in wordpress (CVE-2026-16295)
vulnerability in wordpress (CVE-2026-16295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15233 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15233)
cross-site scripting in wordpress (CVE-2026-15233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14939 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-14939)
SSRF in wordpress (CVE-2026-14939). Confidential information can be exposed externally.
|
| CVE-2026-15958 |
|
Vulnerability in wordpress (CVE-2026-15958)
vulnerability in wordpress (CVE-2026-15958). Confidential information can be exposed externally.
|
| CVE-2026-16035 |
|
Vulnerability in wordpress (CVE-2026-16035)
vulnerability in wordpress (CVE-2026-16035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16056 |
|
Vulnerability in wordpress (CVE-2026-16056)
vulnerability in wordpress (CVE-2026-16056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16069 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16069)
cross-site scripting in wordpress (CVE-2026-16069). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16070 |
|
Vulnerability in wordpress (CVE-2026-16070)
vulnerability in wordpress (CVE-2026-16070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16068 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16068)
cross-site scripting in wordpress (CVE-2026-16068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16293 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16293)
cross-site scripting in wordpress (CVE-2026-16293). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14872 |
|
SQL Injection in wordpress (CVE-2026-14872)
SQL injection in wordpress (CVE-2026-14872). Confidential information can be exposed externally.
|
| CVE-2026-14848 |
|
Vulnerability in wordpress (CVE-2026-14848)
vulnerability in wordpress (CVE-2026-14848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14824 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14824)
cross-site scripting in wordpress (CVE-2026-14824). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14816 |
|
Vulnerability in wordpress (CVE-2026-14816)
vulnerability in wordpress (CVE-2026-14816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12698 |
|
Vulnerability in wordpress (CVE-2026-12698)
vulnerability in wordpress (CVE-2026-12698). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11366 |
|
Authentication Bypass in wordpress (CVE-2026-11366)
authentication bypass in wordpress (CVE-2026-11366). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10526 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-10526)
SSRF in wordpress (CVE-2026-10526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16565 |
|
Vulnerability in wordpress (CVE-2026-16565)
vulnerability in wordpress (CVE-2026-16565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16572 |
|
SQL Injection in wordpress (CVE-2026-16572)
SQL injection in wordpress (CVE-2026-16572). Confidential information can be exposed externally.
|
| CVE-2026-16300 |
|
Vulnerability in wordpress (CVE-2026-16300)
vulnerability in wordpress (CVE-2026-16300). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16532 |
|
SQL Injection in wordpress (CVE-2026-16532)
SQL injection in wordpress (CVE-2026-16532). Confidential information can be exposed externally.
|
| CVE-2026-16297 |
|
Unsafe Deserialization in wordpress (CVE-2026-16297)
vulnerability in wordpress (CVE-2026-16297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16289 |
|
Vulnerability in wordpress (CVE-2026-16289)
vulnerability in wordpress (CVE-2026-16289). Risk of unauthorized operations or information disclosure.
|