Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18391 |
|
Unrestricted File Upload in wordpress (CVE-2026-18391)
vulnerability in wordpress (CVE-2026-18391). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16538 |
|
Vulnerability in wordpress (CVE-2026-16538)
vulnerability in wordpress (CVE-2026-16538). Confidential information can be exposed externally.
|
| CVE-2026-18366 |
|
Privilege Escalation in wordpress (CVE-2026-18366)
vulnerability in wordpress (CVE-2026-18366). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16051 |
|
Code Injection in wordpress (CVE-2026-16051)
code injection in wordpress (CVE-2026-16051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15039 |
|
Unrestricted File Upload in wordpress (CVE-2026-15039)
vulnerability in wordpress (CVE-2026-15039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16230 |
|
Vulnerability in wordpress (CVE-2026-16230)
vulnerability in wordpress (CVE-2026-16230). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19089 |
|
Unrestricted File Upload in wordpress (CVE-2026-19089)
vulnerability in wordpress (CVE-2026-19089). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19053 |
|
SQL Injection in wordpress (CVE-2026-19053)
SQL injection in wordpress (CVE-2026-19053). Confidential information can be exposed externally.
|
| CVE-2026-16299 |
|
Authentication Bypass in wordpress (CVE-2026-16299)
authentication bypass in wordpress (CVE-2026-16299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16298 |
|
Privilege Escalation in wordpress (CVE-2026-16298)
vulnerability in wordpress (CVE-2026-16298). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18473 |
|
SQL Injection in wordpress (CVE-2026-18473)
SQL injection in wordpress (CVE-2026-18473). Confidential information can be exposed externally.
|
| CVE-2026-15038 |
|
Authentication Bypass in wordpress (CVE-2026-15038)
authentication bypass in wordpress (CVE-2026-15038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14526 |
|
Privilege Escalation in wordpress (CVE-2026-14526)
vulnerability in wordpress (CVE-2026-14526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16258 |
|
Unsafe Deserialization in wordpress (CVE-2026-16258)
vulnerability in wordpress (CVE-2026-16258). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14205 |
|
Authentication Bypass in wordpress (CVE-2026-14205)
authentication bypass in wordpress (CVE-2026-14205). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16038 |
|
Vulnerability in wordpress (CVE-2026-16038)
vulnerability in wordpress (CVE-2026-16038). Confidential information can be exposed externally.
|
| CVE-2026-14365 |
|
Vulnerability in wordpress (CVE-2026-14365)
vulnerability in wordpress (CVE-2026-14365). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14364 |
|
Vulnerability in wordpress (CVE-2026-14364)
vulnerability in wordpress (CVE-2026-14364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14812 |
|
Vulnerability in wordpress (CVE-2026-14812)
vulnerability in wordpress (CVE-2026-14812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66447 |
|
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
|
| CVE-2026-16054 |
|
Vulnerability in wordpress (CVE-2026-16054)
vulnerability in wordpress (CVE-2026-16054). Data can be tampered with by attackers.
|
| CVE-2026-12713 |
|
SQL Injection in wordpress (CVE-2026-12713)
SQL injection in wordpress (CVE-2026-12713). Confidential information can be exposed externally.
|
| CVE-2026-5581 |
|
Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
|
| CVE-2026-4431 |
|
Vulnerability in wordpress (CVE-2026-4431)
vulnerability in wordpress (CVE-2026-4431). Data can be tampered with by attackers. Exploitable via ``rbsm_submit_post``.
|
| CVE-2026-16940 |
|
Path Traversal in wordpress (CVE-2026-16940)
path traversal in wordpress (CVE-2026-16940). Data can be tampered with by attackers.
|
| CVE-2026-15360 |
|
SQL Injection in wordpress (CVE-2026-15360)
SQL injection in wordpress (CVE-2026-15360). Confidential information can be exposed externally.
|
| CVE-2026-15210 |
|
Authentication Bypass in wordpress (CVE-2026-15210)
authentication bypass in wordpress (CVE-2026-15210). Confidential information can be exposed externally.
|
| CVE-2026-9273 |
|
Vulnerability in wordpress (CVE-2026-9273)
vulnerability in wordpress (CVE-2026-9273). Confidential information can be exposed externally.
|
| CVE-2026-16618 |
|
Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15958 |
|
Vulnerability in wordpress (CVE-2026-15958)
vulnerability in wordpress (CVE-2026-15958). Confidential information can be exposed externally.
|
| CVE-2026-16534 |
|
Privilege Escalation in wordpress (CVE-2026-16534)
vulnerability in wordpress (CVE-2026-16534). Confidential information can be exposed externally.
|
| CVE-2026-16532 |
|
SQL Injection in wordpress (CVE-2026-16532)
SQL injection in wordpress (CVE-2026-16532). Confidential information can be exposed externally.
|
| CVE-2026-16300 |
|
Vulnerability in wordpress (CVE-2026-16300)
vulnerability in wordpress (CVE-2026-16300). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16250 |
|
Unrestricted File Upload in wordpress (CVE-2026-16250)
vulnerability in wordpress (CVE-2026-16250). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16060 |
|
Unrestricted File Upload in wordpress (CVE-2026-16060)
vulnerability in wordpress (CVE-2026-16060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15930 |
|
Vulnerability in wordpress (CVE-2026-15930)
vulnerability in wordpress (CVE-2026-15930). Data can be tampered with by attackers.
|
| CVE-2026-14557 |
|
Authentication Bypass in wordpress (CVE-2026-14557)
authentication bypass in wordpress (CVE-2026-14557). Confidential information can be exposed externally.
|
| CVE-2026-12965 |
|
SQL Injection in wordpress (CVE-2026-12965)
SQL injection in wordpress (CVE-2026-12965). Confidential information can be exposed externally.
|
| CVE-2026-12872 |
|
Unrestricted File Upload in wordpress (CVE-2026-12872)
vulnerability in wordpress (CVE-2026-12872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16256 |
|
Privilege Escalation in wordpress (CVE-2026-16256)
vulnerability in wordpress (CVE-2026-16256). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8457 |
|
Vulnerability in wordpress (CVE-2026-8457)
vulnerability in wordpress (CVE-2026-8457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15964 |
|
Vulnerability in wordpress (CVE-2026-15964)
vulnerability in wordpress (CVE-2026-15964). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_ssoprocess_ajax``.
|
| CVE-2026-13596 |
|
SQL Injection in wordpress (CVE-2026-13596)
SQL injection in wordpress (CVE-2026-13596). Confidential information can be exposed externally.
|
| CVE-2026-3141 |
|
Vulnerability in wordpress (CVE-2026-3141)
vulnerability in wordpress (CVE-2026-3141). Data can be tampered with by attackers.
|
| CVE-2026-14919 |
|
Authentication Bypass in wordpress (CVE-2026-14919)
authentication bypass in wordpress (CVE-2026-14919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14483 |
|
Unrestricted File Upload in wordpress (CVE-2026-14483)
vulnerability in wordpress (CVE-2026-14483). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14602 |
|
Code Injection in wordpress (CVE-2026-14602)
code injection in wordpress (CVE-2026-14602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16610 |
|
Unrestricted File Upload in wordpress (CVE-2026-16610)
vulnerability in wordpress (CVE-2026-16610). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14488 |
|
Vulnerability in wordpress (CVE-2026-14488)
vulnerability in wordpress (CVE-2026-14488). Data can be tampered with by attackers.
|
| CVE-2026-14900 |
|
Code Injection in wordpress (CVE-2026-14900)
code injection in wordpress (CVE-2026-14900). Successful exploitation can lead to full system takeover.
|