Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9719 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9719)
vulnerability in wordpress (CVE-2026-9719). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6448 |
|
SQL Injection in wordpress (CVE-2026-6448)
SQL injection in wordpress (CVE-2026-6448). Confidential information can be exposed externally.
|
| CVE-2026-7047 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7047)
vulnerability in wordpress (CVE-2026-7047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8608 |
|
Vulnerability in wordpress (CVE-2026-8608)
vulnerability in wordpress (CVE-2026-8608). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8893 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8893)
cross-site scripting in wordpress (CVE-2026-8893). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12656 |
|
Vulnerability in wordpress (CVE-2025-12656)
vulnerability in wordpress (CVE-2025-12656). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10038 |
|
Vulnerability in wordpress (CVE-2026-10038)
vulnerability in wordpress (CVE-2026-10038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7523 |
|
Vulnerability in wordpress (CVE-2026-7523)
vulnerability in wordpress (CVE-2026-7523). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7654 |
|
Unsafe Deserialization in wordpress (CVE-2026-7654)
vulnerability in wordpress (CVE-2026-7654). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
|
| CVE-2026-5415 |
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
| CVE-2026-5411 |
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
| CVE-2026-10580 |
|
Vulnerability in wordpress (CVE-2026-10580)
vulnerability in wordpress (CVE-2026-10580). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10586 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-10586)
SSRF in wordpress (CVE-2026-10586). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25742 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25742)
cross-site scripting in wordpress (CVE-2019-25742). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25744 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25744)
cross-site scripting in wordpress (CVE-2019-25744). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25745 |
|
SQL Injection in wordpress (CVE-2019-25745)
SQL injection in wordpress (CVE-2019-25745). Confidential information can be exposed externally.
|
| CVE-2019-25738 |
|
Vulnerability in wordpress (CVE-2019-25738)
vulnerability in wordpress (CVE-2019-25738). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25743 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25743)
cross-site scripting in wordpress (CVE-2019-25743). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25727 |
|
Path Traversal in wordpress (CVE-2019-25727)
path traversal in wordpress (CVE-2019-25727). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10737 |
|
Vulnerability in wordpress (CVE-2026-10737)
vulnerability in wordpress (CVE-2026-10737). Confidential information can be exposed externally.
|
| CVE-2026-8653 |
|
SQL Injection in wordpress (CVE-2026-8653)
SQL injection in wordpress (CVE-2026-8653). Confidential information can be exposed externally.
|
| CVE-2026-10770 |
|
Cross-Site Scripting (XSS) in drupal/cleantalk (CVE-2026-10770)
cross-site scripting in drupal/cleantalk (CVE-2026-10770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-10769 |
|
Cross-Site Scripting (XSS) in drupal/commerce (CVE-2026-10769)
cross-site scripting in drupal/commerce (CVE-2026-10769). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.6` or later.
|
| CVE-2026-10768 |
|
Vulnerability in drupal/localgov_workflows (CVE-2026-10768)
vulnerability in drupal/localgov_workflows (CVE-2026-10768). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.0` or later.
|
| CVE-2026-9732 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9732)
vulnerability in wordpress (CVE-2026-9732). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7421 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7421)
cross-site scripting in wordpress (CVE-2026-7421). Risk of unauthorized operations or information disclosure. Exploitable via ``shop_name``.
|
| CVE-2026-5073 |
|
SQL Injection in wordpress (CVE-2026-5073)
SQL injection in wordpress (CVE-2026-5073). Confidential information can be exposed externally.
|
| CVE-2026-5074 |
|
SQL Injection in wordpress (CVE-2026-5074)
SQL injection in wordpress (CVE-2026-5074). Confidential information can be exposed externally. Exploitable via ``get_private_content_data``.
|
| CVE-2026-5076 |
|
Authentication Bypass in wordpress (CVE-2026-5076)
authentication bypass in wordpress (CVE-2026-5076). Successful exploitation can lead to full system takeover. Exploitable via ``arm_reset_password_key``.
|
| CVE-2026-1829 |
|
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
|
| CVE-2026-39552 |
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
| CVE-2026-39553 |
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
| CVE-2026-39555 |
|
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
...
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
...
|
| CVE-2025-68886 |
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
| CVE-2025-69369 |
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
| CVE-2026-5191 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5191)
cross-site scripting in wordpress (CVE-2026-5191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8885 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8885)
cross-site scripting in wordpress (CVE-2026-8885). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-5085 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-5085)
cross-site scripting in wordpress (CVE-2025-5085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1451 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-1451)
cross-site scripting in wordpress (CVE-2026-1451). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1450 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-1450)
cross-site scripting in wordpress (CVE-2026-1450). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4071 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-4071)
vulnerability in wordpress (CVE-2026-4071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2382 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2382)
cross-site scripting in wordpress (CVE-2026-2382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9722 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9722)
vulnerability in wordpress (CVE-2026-9722). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9234 |
|
Vulnerability in wordpress (CVE-2026-9234)
vulnerability in wordpress (CVE-2026-9234). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8422 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-8422)
vulnerability in wordpress (CVE-2026-8422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9599 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9599)
vulnerability in wordpress (CVE-2026-9599). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9730 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9730)
vulnerability in wordpress (CVE-2026-9730). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9723 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9723)
vulnerability in wordpress (CVE-2026-9723). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2425 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2425)
cross-site scripting in wordpress (CVE-2026-2425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3620 |
|
Vulnerability in wordpress (CVE-2026-3620)
vulnerability in wordpress (CVE-2026-3620). Risk of unauthorized operations or information disclosure.
|