Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15312 |
|
Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-15341 |
|
Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-15303 |
|
Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15001 |
|
Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
|
| CVE-2026-16080 |
|
SQL Injection in wordpress (CVE-2026-16080)
SQL injection in wordpress (CVE-2026-16080). Confidential information can be exposed externally.
|
| CVE-2026-12128 |
|
Vulnerability in wordpress (CVE-2026-12128)
vulnerability in wordpress (CVE-2026-12128). Risk of unauthorized operations or information disclosure. Exploitable via ``cart_data``.
|
| CVE-2026-14484 |
|
Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
|
| CVE-2026-14433 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12365 |
|
Use-After-Free in c (CVE-2026-12365)
vulnerability in c (CVE-2026-12365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19794 |
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
| CVE-2026-18039 |
|
Privilege Escalation in wordpress (CVE-2026-18039)
vulnerability in wordpress (CVE-2026-18039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15205 |
|
SQL Injection in wordpress (CVE-2026-15205)
SQL injection in wordpress (CVE-2026-15205). Confidential information can be exposed externally.
|
| CVE-2026-12743 |
|
SQL Injection in wordpress (CVE-2026-12743)
SQL injection in wordpress (CVE-2026-12743). Confidential information can be exposed externally.
|
| CVE-2026-16739 |
|
Authentication Bypass in wordpress (CVE-2026-16739)
authentication bypass in wordpress (CVE-2026-16739). Data can be tampered with by attackers.
|
| CVE-2026-12949 |
|
Vulnerability in wordpress (CVE-2026-12949)
vulnerability in wordpress (CVE-2026-12949). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16810 |
|
SQL Injection in wordpress (CVE-2026-16810)
SQL injection in wordpress (CVE-2026-16810). Confidential information can be exposed externally.
|
| CVE-2026-14290 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14290)
cross-site scripting in wordpress (CVE-2026-14290). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10308 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2025-10308)
vulnerability in wordpress (CVE-2025-10308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18109 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18109)
cross-site scripting in wordpress (CVE-2026-18109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-28154)
cross-site scripting in wordpress (CVE-2026-28154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66426 |
|
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
|
| CVE-2026-15413 |
|
Vulnerability in wordpress (CVE-2026-15413)
vulnerability in wordpress (CVE-2026-15413). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14332 |
|
Vulnerability in wordpress (CVE-2026-14332)
vulnerability in wordpress (CVE-2026-14332). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3639 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3639)
cross-site scripting in wordpress (CVE-2026-3639). Risk of unauthorized operations or information disclosure. Exploitable via ``ppwp``.
|
| CVE-2026-18146 |
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
| CVE-2026-3835 |
|
Vulnerability in wordpress (CVE-2026-3835)
vulnerability in wordpress (CVE-2026-3835). Risk of unauthorized operations or information disclosure. Exploitable via ``LIKE``.
|
| CVE-2026-19088 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-19088)
vulnerability in wordpress (CVE-2026-19088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14182 |
|
Authentication Bypass in wordpress (CVE-2026-14182)
authentication bypass in wordpress (CVE-2026-14182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13328 |
|
Vulnerability in wordpress (CVE-2026-13328)
vulnerability in wordpress (CVE-2026-13328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18945 |
|
Vulnerability in wordpress (CVE-2026-18945)
vulnerability in wordpress (CVE-2026-18945). Data can be tampered with by attackers.
|
| CVE-2026-13610 |
|
Privilege Escalation in wordpress (CVE-2026-13610)
vulnerability in wordpress (CVE-2026-13610). Confidential information can be exposed externally.
|
| CVE-2026-14213 |
|
Vulnerability in wordpress (CVE-2026-14213)
vulnerability in wordpress (CVE-2026-14213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49466 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-49466)
cross-site scripting in wordpress (CVE-2026-49466). Risk of unauthorized operations or information disclosure. Exploitable via ``template``.
|
| CVE-2026-17008 |
|
Vulnerability in wordpress (CVE-2026-17008)
vulnerability in wordpress (CVE-2026-17008). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18044 |
|
Vulnerability in wordpress (CVE-2026-18044)
vulnerability in wordpress (CVE-2026-18044). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16747 |
|
Vulnerability in wordpress (CVE-2026-16747)
vulnerability in wordpress (CVE-2026-16747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15213 |
|
Vulnerability in wordpress (CVE-2026-15213)
vulnerability in wordpress (CVE-2026-15213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16621 |
|
Vulnerability in c (CVE-2026-16621)
vulnerability in c (CVE-2026-16621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16990 |
|
Vulnerability in wordpress (CVE-2026-16990)
vulnerability in wordpress (CVE-2026-16990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15045 |
|
Vulnerability in wordpress (CVE-2026-15045)
vulnerability in wordpress (CVE-2026-15045). Data can be tampered with by attackers.
|
| CVE-2026-19050 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-19050)
SSRF in wordpress (CVE-2026-19050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18230 |
|
SQL Injection in wordpress (CVE-2026-18230)
SQL injection in wordpress (CVE-2026-18230). Confidential information can be exposed externally.
|
| CVE-2026-18046 |
|
Authorization Flaw in wordpress (CVE-2026-18046)
vulnerability in wordpress (CVE-2026-18046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16977 |
|
SQL Injection in wordpress (CVE-2026-16977)
SQL injection in wordpress (CVE-2026-16977). Confidential information can be exposed externally.
|
| CVE-2026-16737 |
|
Vulnerability in wordpress (CVE-2026-16737)
vulnerability in wordpress (CVE-2026-16737). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16253 |
|
Information Disclosure in wordpress (CVE-2026-16253)
vulnerability in wordpress (CVE-2026-16253). Confidential information can be exposed externally.
|
| CVE-2026-15388 |
|
Authorization Flaw in wordpress (CVE-2026-15388)
vulnerability in wordpress (CVE-2026-15388). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18057 |
|
SQL Injection in wordpress (CVE-2026-18057)
SQL injection in wordpress (CVE-2026-18057). Confidential information can be exposed externally.
|