Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66602 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-66602)
vulnerability in wordpress (CVE-2026-66602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-73351)
cross-site scripting in wordpress (CVE-2026-73351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15748 |
|
Unrestricted File Upload in wordpress (CVE-2026-15748)
vulnerability in wordpress (CVE-2026-15748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75091 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75091)
cross-site scripting in wordpress (CVE-2026-75091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11801 |
|
Vulnerability in wordpress (CVE-2026-11801)
vulnerability in wordpress (CVE-2026-11801). Confidential information can be exposed externally.
|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-14832 |
|
Vulnerability in wordpress (CVE-2026-14832)
vulnerability in wordpress (CVE-2026-14832). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13700 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13700)
SSRF in wordpress (CVE-2026-13700). Confidential information can be exposed externally.
|
| CVE-2024-13784 |
|
Unsafe Deserialization in wordpress (CVE-2024-13784)
vulnerability in wordpress (CVE-2024-13784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2497 |
|
SQL Injection in wordpress (CVE-2026-2497)
SQL injection in wordpress (CVE-2026-2497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10734 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10734)
cross-site scripting in wordpress (CVE-2026-10734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2357 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2357)
cross-site scripting in wordpress (CVE-2026-2357). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18347 |
|
Vulnerability in wordpress (CVE-2026-18347)
vulnerability in wordpress (CVE-2026-18347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17608 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-17608)
vulnerability in wordpress (CVE-2026-17608). Data can be tampered with by attackers.
|
| CVE-2026-17604 |
|
Path Traversal in wordpress (CVE-2026-17604)
path traversal in wordpress (CVE-2026-17604). Confidential information can be exposed externally.
|
| CVE-2026-17087 |
|
Vulnerability in wordpress (CVE-2026-17087)
vulnerability in wordpress (CVE-2026-17087). Confidential information can be exposed externally.
|
| CVE-2026-13424 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13424)
cross-site scripting in wordpress (CVE-2026-13424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12998 |
|
Vulnerability in wordpress (CVE-2026-12998)
vulnerability in wordpress (CVE-2026-12998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9767 |
|
SQL Injection in wordpress (CVE-2026-9767)
SQL injection in wordpress (CVE-2026-9767). Confidential information can be exposed externally.
|
| CVE-2026-18653 |
|
SQL Injection in wordpress (CVE-2026-18653)
SQL injection in wordpress (CVE-2026-18653). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19714 |
|
Authentication Bypass in wordpress (CVE-2026-19714)
authentication bypass in wordpress (CVE-2026-19714). Confidential information can be exposed externally.
|
| CVE-2026-18402 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18402)
cross-site scripting in wordpress (CVE-2026-18402). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17582 |
|
SQL Injection in wordpress (CVE-2026-17582)
SQL injection in wordpress (CVE-2026-17582). Confidential information can be exposed externally.
|
| CVE-2026-18316 |
|
Vulnerability in wordpress (CVE-2026-18316)
vulnerability in wordpress (CVE-2026-18316). Data can be tampered with by attackers.
|
| CVE-2026-19728 |
|
Vulnerability in wordpress (CVE-2026-19728)
vulnerability in wordpress (CVE-2026-19728). Confidential information can be exposed externally.
|
| CVE-2026-19726 |
|
Authorization Flaw in wordpress (CVE-2026-19726)
vulnerability in wordpress (CVE-2026-19726). Confidential information can be exposed externally.
|
| CVE-2026-2283 |
|
SQL Injection in wordpress (CVE-2026-2283)
SQL injection in wordpress (CVE-2026-2283). Confidential information can be exposed externally.
|
| CVE-2026-19717 |
|
Information Disclosure in wordpress (CVE-2026-19717)
vulnerability in wordpress (CVE-2026-19717). Confidential information can be exposed externally.
|
| CVE-2026-19725 |
|
Path Traversal in wordpress (CVE-2026-19725)
path traversal in wordpress (CVE-2026-19725). Confidential information can be exposed externally.
|
| CVE-2026-19711 |
|
Vulnerability in wordpress (CVE-2026-19711)
vulnerability in wordpress (CVE-2026-19711). Data can be tampered with by attackers.
|
| CVE-2026-19613 |
|
Information Disclosure in wordpress (CVE-2026-19613)
vulnerability in wordpress (CVE-2026-19613). Confidential information can be exposed externally.
|
| CVE-2026-19712 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19712)
cross-site scripting in wordpress (CVE-2026-19712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15384 |
|
Authentication Bypass in wordpress (CVE-2026-15384)
authentication bypass in wordpress (CVE-2026-15384). Data can be tampered with by attackers.
|
| CVE-2026-15066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15066)
cross-site scripting in wordpress (CVE-2026-15066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15602 |
|
SQL Injection in wordpress (CVE-2026-15602)
SQL injection in wordpress (CVE-2026-15602). Confidential information can be exposed externally.
|
| CVE-2026-16779 |
|
Vulnerability in wordpress (CVE-2026-16779)
vulnerability in wordpress (CVE-2026-16779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18385 |
|
Code Injection in wordpress (CVE-2026-18385)
code injection in wordpress (CVE-2026-18385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15441 |
|
Vulnerability in wordpress (CVE-2026-15441)
vulnerability in wordpress (CVE-2026-15441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13712 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13712)
cross-site scripting in wordpress (CVE-2026-13712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15604 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15604)
cross-site scripting in wordpress (CVE-2026-15604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16099 |
|
Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17123 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17123)
SSRF in wordpress (CVE-2026-17123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17533 |
|
Privilege Escalation in wordpress (CVE-2026-17533)
vulnerability in wordpress (CVE-2026-17533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16758 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16758)
cross-site scripting in wordpress (CVE-2026-16758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16775 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16775)
cross-site scripting in wordpress (CVE-2026-16775). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10035 |
|
Unsafe Deserialization in wordpress (CVE-2026-10035)
vulnerability in wordpress (CVE-2026-10035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15790 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15790)
cross-site scripting in wordpress (CVE-2026-15790). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17581 |
|
Code Injection in wordpress (CVE-2026-17581)
code injection in wordpress (CVE-2026-17581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15056 |
|
Path Traversal in wordpress (CVE-2026-15056)
path traversal in wordpress (CVE-2026-15056). Confidential information can be exposed externally.
|
| CVE-2026-15351 |
|
SQL Injection in wordpress (CVE-2026-15351)
SQL injection in wordpress (CVE-2026-15351). Confidential information can be exposed externally.
|