Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cms Clear
ID Title
CVE-2026-3296 Unsafe Deserialization in wordpress (CVE-2026-3296)
vulnerability in wordpress (CVE-2026-3296). Successful exploitation can lead to full system takeover.
CVE-2025-14732 Vulnerability in wordpress (CVE-2025-14732)
vulnerability in wordpress (CVE-2025-14732). Risk of unauthorized operations or information disclosure.
CVE-2026-4065 Vulnerability in wordpress (CVE-2026-4065)
vulnerability in wordpress (CVE-2026-4065). Risk of unauthorized operations or information disclosure.
CVE-2026-2936 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2936)
cross-site scripting in wordpress (CVE-2026-2936). Risk of unauthorized operations or information disclosure.
CVE-2026-3309 Code Injection in wordpress (CVE-2026-3309)
code injection in wordpress (CVE-2026-3309). Risk of unauthorized operations or information disclosure.
CVE-2026-3666 Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
CVE-2026-1233 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing...
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TT...
CVE-2026-0626 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0626)
cross-site scripting in wordpress (CVE-2026-0626). Risk of unauthorized operations or information disclosure.
CVE-2025-14938 Unrestricted File Upload in wordpress (CVE-2025-14938)
vulnerability in wordpress (CVE-2025-14938). Risk of unauthorized operations or information disclosure.
CVE-2026-2826 Vulnerability in wordpress (CVE-2026-2826)
vulnerability in wordpress (CVE-2026-2826). Risk of unauthorized operations or information disclosure. Exploitable via ``upload_files``.
CVE-2026-3445 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass i...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the...
CVE-2026-5425 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5425)
cross-site scripting in wordpress (CVE-2026-5425). Risk of unauthorized operations or information disclosure.
CVE-2026-2437 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2437)
cross-site scripting in wordpress (CVE-2026-2437). Risk of unauthorized operations or information disclosure.
CVE-2026-4896 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`,...
CVE-2026-0737 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0737)
cross-site scripting in wordpress (CVE-2026-0737). Risk of unauthorized operations or information disclosure.
CVE-2026-0738 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0738)
cross-site scripting in wordpress (CVE-2026-0738). Risk of unauthorized operations or information disclosure.
CVE-2026-2600 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2600)
cross-site scripting in wordpress (CVE-2026-2600). Risk of unauthorized operations or information disclosure.
CVE-2025-15064 Cross-Site Scripting (XSS) in wordpress (CVE-2025-15064)
cross-site scripting in wordpress (CVE-2025-15064). Risk of unauthorized operations or information disclosure.
CVE-2026-0552 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0552)
cross-site scripting in wordpress (CVE-2026-0552). Risk of unauthorized operations or information disclosure.
CVE-2026-0664 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0664)
cross-site scripting in wordpress (CVE-2026-0664). Risk of unauthorized operations or information disclosure.
CVE-2025-13368 Cross-Site Scripting (XSS) in wordpress (CVE-2025-13368)
cross-site scripting in wordpress (CVE-2025-13368). Risk of unauthorized operations or information disclosure.
CVE-2026-2949 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2949)
cross-site scripting in wordpress (CVE-2026-2949). Risk of unauthorized operations or information disclosure.
CVE-2026-2924 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2924)
cross-site scripting in wordpress (CVE-2026-2924). Risk of unauthorized operations or information disclosure.
CVE-2026-3571 Vulnerability in wordpress (CVE-2026-3571)
vulnerability in wordpress (CVE-2026-3571). Risk of unauthorized operations or information disclosure.
CVE-2026-4350 The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
CVE-2026-34973 Vulnerability in phpmyfaq (CVE-2026-34973)
vulnerability in phpmyfaq (CVE-2026-34973). Risk of unauthorized operations or information disclosure.
CVE-2026-34974 Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-34974)
cross-site scripting in privilege-escalation (CVE-2026-34974). Risk of unauthorized operations or information disclosure.
CVE-2026-4267 Cross-Site Scripting (XSS) in wordpress (CVE-2026-4267)
cross-site scripting in wordpress (CVE-2026-4267). Risk of unauthorized operations or information disclosure.
CVE-2026-3139 Vulnerability in wordpress (CVE-2026-3139)
vulnerability in wordpress (CVE-2026-3139). Risk of unauthorized operations or information disclosure.
CVE-2026-3191 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-3191)
vulnerability in wordpress (CVE-2026-3191). Risk of unauthorized operations or information disclosure.
CVE-2026-33559 Cross-Site Scripting (XSS) in wordpress (CVE-2026-33559)
cross-site scripting in wordpress (CVE-2026-33559). Risk of unauthorized operations or information disclosure.
CVE-2026-21361 Cross-Site Scripting (XSS) in adobe (CVE-2026-21361)
cross-site scripting in adobe (CVE-2026-21361). Confidential information can be exposed externally.
CVE-2026-21309 Authorization Flaw in adobe (CVE-2026-21309)
vulnerability in adobe (CVE-2026-21309). Confidential information can be exposed externally.
CVE-2026-21310 Vulnerability in adobe (CVE-2026-21310)
vulnerability in adobe (CVE-2026-21310). Risk of unauthorized operations or information disclosure.
CVE-2026-21311 Cross-Site Scripting (XSS) in adobe (CVE-2026-21311)
cross-site scripting in adobe (CVE-2026-21311). Confidential information can be exposed externally.
CVE-2026-21359 Authorization Flaw in adobe (CVE-2026-21359)
vulnerability in adobe (CVE-2026-21359). Risk of unauthorized operations or information disclosure.
CVE-2026-21360 Path Traversal in path-traversal (CVE-2026-21360)
path traversal in path-traversal (CVE-2026-21360). Confidential information can be exposed externally.
CVE-2026-21292 Cross-Site Scripting (XSS) in adobe (CVE-2026-21292)
cross-site scripting in adobe (CVE-2026-21292). Risk of unauthorized operations or information disclosure.
CVE-2026-21293 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-21293)
SSRF in ssrf (CVE-2026-21293). Risk of unauthorized operations or information disclosure.
CVE-2026-21294 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-21294)
SSRF in ssrf (CVE-2026-21294). Risk of unauthorized operations or information disclosure.
CVE-2026-21295 Open Redirect in c (CVE-2026-21295)
vulnerability in c (CVE-2026-21295). Risk of unauthorized operations or information disclosure.
CVE-2026-21296 Authorization Flaw in adobe (CVE-2026-21296)
vulnerability in adobe (CVE-2026-21296). Risk of unauthorized operations or information disclosure.
CVE-2026-21297 Authorization Flaw in adobe (CVE-2026-21297)
vulnerability in adobe (CVE-2026-21297). Risk of unauthorized operations or information disclosure.
CVE-2026-21284 Cross-Site Scripting (XSS) in adobe (CVE-2026-21284)
cross-site scripting in adobe (CVE-2026-21284). Confidential information can be exposed externally.
CVE-2026-21285 Authorization Flaw in adobe (CVE-2026-21285)
vulnerability in adobe (CVE-2026-21285). Risk of unauthorized operations or information disclosure.
CVE-2026-21286 Authorization Flaw in adobe (CVE-2026-21286)
vulnerability in adobe (CVE-2026-21286). Risk of unauthorized operations or information disclosure.
CVE-2026-21289 Authorization Flaw in adobe (CVE-2026-21289)
vulnerability in adobe (CVE-2026-21289). Confidential information can be exposed externally.
CVE-2026-21290 Cross-Site Scripting (XSS) in adobe (CVE-2026-21290)
cross-site scripting in adobe (CVE-2026-21290). Confidential information can be exposed externally.
CVE-2026-21291 Cross-Site Scripting (XSS) in adobe (CVE-2026-21291)
cross-site scripting in adobe (CVE-2026-21291). Risk of unauthorized operations or information disclosure.
CVE-2026-21282 Vulnerability in adobe (CVE-2026-21282)
vulnerability in adobe (CVE-2026-21282). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →