Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14292 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14292)
cross-site scripting in wordpress (CVE-2026-14292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14214 |
|
Authentication Bypass in wordpress (CVE-2026-14214)
authentication bypass in wordpress (CVE-2026-14214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14197 |
|
Vulnerability in wordpress (CVE-2026-14197)
vulnerability in wordpress (CVE-2026-14197). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14195 |
|
Vulnerability in wordpress (CVE-2026-14195)
vulnerability in wordpress (CVE-2026-14195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13729 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-13729)
vulnerability in wordpress (CVE-2026-13729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13725 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13725)
cross-site scripting in wordpress (CVE-2026-13725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13604 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13604)
SSRF in wordpress (CVE-2026-13604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13596 |
|
SQL Injection in wordpress (CVE-2026-13596)
SQL injection in wordpress (CVE-2026-13596). Confidential information can be exposed externally.
|
| CVE-2026-13329 |
|
Vulnerability in wordpress (CVE-2026-13329)
vulnerability in wordpress (CVE-2026-13329). Data can be tampered with by attackers.
|
| CVE-2026-13158 |
|
Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13157 |
|
Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12966 |
|
Vulnerability in wordpress (CVE-2026-12966)
vulnerability in wordpress (CVE-2026-12966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12696 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12696)
cross-site scripting in wordpress (CVE-2026-12696). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11882 |
|
Vulnerability in wordpress (CVE-2026-11882)
vulnerability in wordpress (CVE-2026-11882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10827 |
|
Vulnerability in wordpress (CVE-2026-10827)
vulnerability in wordpress (CVE-2026-10827). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15669 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15669)
cross-site scripting in wordpress (CVE-2025-15669). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3141 |
|
Vulnerability in wordpress (CVE-2026-3141)
vulnerability in wordpress (CVE-2026-3141). Data can be tampered with by attackers.
|
| CVE-2026-7623 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7623)
cross-site scripting in wordpress (CVE-2026-7623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-15403 |
|
SQL Injection in wordpress (CVE-2026-15403)
SQL injection in wordpress (CVE-2026-15403). Confidential information can be exposed externally.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-13362 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13362)
cross-site scripting in wordpress (CVE-2026-13362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54768 |
|
Vulnerability in wp-graphql/wp-graphql (CVE-2026-54768)
vulnerability in wp-graphql/wp-graphql (CVE-2026-54768). Risk of unauthorized operations or information disclosure. Exploitable via ``sendPasswordResetEmail``.
|
| CVE-2026-17567 |
|
Vulnerability in wordpress (CVE-2026-17567)
vulnerability in wordpress (CVE-2026-17567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18437 |
|
Vulnerability in wordpress (CVE-2026-18437)
vulnerability in wordpress (CVE-2026-18437). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18436 |
|
Vulnerability in wordpress (CVE-2026-18436)
vulnerability in wordpress (CVE-2026-18436). Risk of unauthorized operations or information disclosure. Exploitable via `POST /wp-json/mailpress/v1/campaign/`.
|
| CVE-2026-8155 |
|
Vulnerability in wordpress (CVE-2026-8155)
vulnerability in wordpress (CVE-2026-8155). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16236 |
|
Unrestricted File Upload in wordpress (CVE-2026-16236)
vulnerability in wordpress (CVE-2026-16236). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15381 |
|
SQL Injection in wordpress (CVE-2026-15381)
SQL injection in wordpress (CVE-2026-15381). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15258 |
|
SQL Injection in wordpress (CVE-2026-15258)
SQL injection in wordpress (CVE-2026-15258). Confidential information can be exposed externally.
|
| CVE-2026-15209 |
|
Vulnerability in wordpress (CVE-2026-15209)
vulnerability in wordpress (CVE-2026-15209). Confidential information can be exposed externally.
|
| CVE-2026-15048 |
|
Information Disclosure in wordpress (CVE-2026-15048)
vulnerability in wordpress (CVE-2026-15048). Confidential information can be exposed externally.
|
| CVE-2026-14931 |
|
Information Disclosure in wordpress (CVE-2026-14931)
vulnerability in wordpress (CVE-2026-14931). Confidential information can be exposed externally.
|
| CVE-2026-14930 |
|
Vulnerability in wordpress (CVE-2026-14930)
vulnerability in wordpress (CVE-2026-14930). Confidential information can be exposed externally.
|
| CVE-2026-14929 |
|
Authorization Flaw in wordpress (CVE-2026-14929)
vulnerability in wordpress (CVE-2026-14929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14928 |
|
Information Disclosure in wordpress (CVE-2026-14928)
vulnerability in wordpress (CVE-2026-14928). Confidential information can be exposed externally.
|
| CVE-2026-14927 |
|
Vulnerability in wordpress (CVE-2026-14927)
vulnerability in wordpress (CVE-2026-14927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14921 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14921)
cross-site scripting in wordpress (CVE-2026-14921). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14833 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14833)
cross-site scripting in wordpress (CVE-2026-14833). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14830 |
|
Authentication Bypass in wordpress (CVE-2026-14830)
authentication bypass in wordpress (CVE-2026-14830). Data can be tampered with by attackers.
|
| CVE-2026-14834 |
|
Vulnerability in wordpress (CVE-2026-14834)
vulnerability in wordpress (CVE-2026-14834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14843 |
|
Vulnerability in wordpress (CVE-2026-14843)
vulnerability in wordpress (CVE-2026-14843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14845 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14845)
cross-site scripting in wordpress (CVE-2026-14845). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14849 |
|
Vulnerability in wordpress (CVE-2026-14849)
vulnerability in wordpress (CVE-2026-14849). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14919 |
|
Authentication Bypass in wordpress (CVE-2026-14919)
authentication bypass in wordpress (CVE-2026-14919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14862 |
|
Vulnerability in wordpress (CVE-2026-14862)
vulnerability in wordpress (CVE-2026-14862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14847 |
|
Vulnerability in wordpress (CVE-2026-14847)
vulnerability in wordpress (CVE-2026-14847). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13609 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13609)
cross-site scripting in wordpress (CVE-2026-13609). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13392 |
|
Code Injection in wordpress (CVE-2026-13392)
code injection in wordpress (CVE-2026-13392). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14317 |
|
Vulnerability in wordpress (CVE-2026-14317)
vulnerability in wordpress (CVE-2026-14317). Risk of unauthorized operations or information disclosure.
|