Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16099 |
|
Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18432 |
|
Privilege Escalation in wordpress (CVE-2026-18432)
vulnerability in wordpress (CVE-2026-18432). Successful exploitation can lead to full system takeover. Exploitable via ``item_id``.
|
| CVE-2026-15345 |
|
Vulnerability in wordpress (CVE-2026-15345)
vulnerability in wordpress (CVE-2026-15345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16079 |
|
SQL Injection in wordpress (CVE-2026-16079)
SQL injection in wordpress (CVE-2026-16079). Confidential information can be exposed externally.
|
| CVE-2026-16098 |
|
Unrestricted File Upload in wordpress (CVE-2026-16098)
vulnerability in wordpress (CVE-2026-16098). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15963 |
|
SQL Injection in wordpress (CVE-2026-15963)
SQL injection in wordpress (CVE-2026-15963). Confidential information can be exposed externally.
|
| CVE-2026-15056 |
|
Path Traversal in wordpress (CVE-2026-15056)
path traversal in wordpress (CVE-2026-15056). Confidential information can be exposed externally.
|
| CVE-2026-15726 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15726)
cross-site scripting in wordpress (CVE-2026-15726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13712 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13712)
cross-site scripting in wordpress (CVE-2026-13712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15441 |
|
Vulnerability in wordpress (CVE-2026-15441)
vulnerability in wordpress (CVE-2026-15441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18385 |
|
Code Injection in wordpress (CVE-2026-18385)
code injection in wordpress (CVE-2026-18385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16779 |
|
Vulnerability in wordpress (CVE-2026-16779)
vulnerability in wordpress (CVE-2026-16779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15602 |
|
SQL Injection in wordpress (CVE-2026-15602)
SQL injection in wordpress (CVE-2026-15602). Confidential information can be exposed externally.
|
| CVE-2026-15066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15066)
cross-site scripting in wordpress (CVE-2026-15066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13358 |
|
Vulnerability in wordpress (CVE-2026-13358)
vulnerability in wordpress (CVE-2026-13358). Confidential information can be exposed externally.
|
| CVE-2026-12905 |
|
Vulnerability in wordpress (CVE-2026-12905)
vulnerability in wordpress (CVE-2026-12905). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15002 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15002)
cross-site scripting in wordpress (CVE-2026-15002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14524 |
|
Path Traversal in wordpress (CVE-2026-14524)
path traversal in wordpress (CVE-2026-14524). Data can be tampered with by attackers.
|
| CVE-2026-13167 |
|
Vulnerability in wordpress (CVE-2026-13167)
vulnerability in wordpress (CVE-2026-13167). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15009 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15009)
cross-site scripting in wordpress (CVE-2026-15009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14498 |
|
Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10005 |
|
Vulnerability in wordpress (CVE-2025-10005)
vulnerability in wordpress (CVE-2025-10005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11780 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11780)
cross-site scripting in wordpress (CVE-2026-11780). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12477 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12477)
cross-site scripting in wordpress (CVE-2026-12477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2487 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2487)
cross-site scripting in wordpress (CVE-2026-2487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18855 |
|
Path Traversal in wordpress (CVE-2026-18855)
path traversal in wordpress (CVE-2026-18855). Data can be tampered with by attackers.
|
| CVE-2026-19598 |
|
Authorization Flaw in wordpress (CVE-2026-19598)
vulnerability in wordpress (CVE-2026-19598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12248 |
|
SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15142 |
|
Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16142 |
|
Vulnerability in wordpress (CVE-2026-16142)
vulnerability in wordpress (CVE-2026-16142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15826 |
|
Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-18807 |
|
Vulnerability in wordpress (CVE-2026-18807)
vulnerability in wordpress (CVE-2026-18807). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18216 |
|
Authentication Bypass in wordpress (CVE-2026-18216)
authentication bypass in wordpress (CVE-2026-18216). Confidential information can be exposed externally.
|
| CVE-2026-16541 |
|
Information Disclosure in wordpress (CVE-2026-16541)
vulnerability in wordpress (CVE-2026-16541). Confidential information can be exposed externally.
|
| CVE-2026-16611 |
|
Information Disclosure in wordpress (CVE-2026-16611)
vulnerability in wordpress (CVE-2026-16611). Confidential information can be exposed externally.
|
| CVE-2026-14230 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14230)
cross-site scripting in wordpress (CVE-2026-14230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14229 |
|
Vulnerability in wordpress (CVE-2026-14229)
vulnerability in wordpress (CVE-2026-14229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18387 |
|
SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
|
| CVE-2026-17090 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16146 |
|
SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16586 |
|
SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
|
| CVE-2026-16094 |
|
SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
|
| CVE-2026-15993 |
|
SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
|
| CVE-2026-15948 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15453 |
|
SQL Injection in wordpress (CVE-2026-15453)
SQL injection in wordpress (CVE-2026-15453). Confidential information can be exposed externally.
|
| CVE-2026-13360 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8840 |
|
Vulnerability in wordpress (CVE-2026-8840)
vulnerability in wordpress (CVE-2026-8840). Risk of unauthorized operations or information disclosure.
|