Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-26980 |
|
SQL Injection in ghost (CVE-2026-26980)
SQL injection in ghost (CVE-2026-26980). Confidential information can be exposed externally. Mitigation: upgrade to `6.19.1` or later.
|
| CVE-2025-14843 |
|
Vulnerability in wordpress (CVE-2025-14843)
vulnerability in wordpress (CVE-2025-14843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0674 |
|
Vulnerability in wordpress (CVE-2026-0674)
vulnerability in wordpress (CVE-2026-0674). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-40079 |
|
Vulnerability in wordpress (CVE-2025-40079)
vulnerability in wordpress (CVE-2025-40079). Successful exploitation can lead to full system takeover.
|
| CVE-2025-54236 KEV |
|
[KEV] Vulnerability in Adobe commerce (CVE-2025-54236)
vulnerability in Adobe commerce (CVE-2025-54236). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2025-11570 |
|
Cross-Site Scripting (XSS) in drupal (CVE-2025-11570)
cross-site scripting in drupal (CVE-2025-11570). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8889 |
|
Unrestricted File Upload in wordpress (CVE-2025-8889)
vulnerability in wordpress (CVE-2025-8889). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8361 |
|
Vulnerability in drupal (CVE-2025-8361)
vulnerability in drupal (CVE-2025-8361). Confidential information can be exposed externally.
|
| CVE-2012-10027 |
|
Unrestricted File Upload in wordpress (CVE-2012-10027)
vulnerability in wordpress (CVE-2012-10027). Risk of unauthorized operations or information disclosure. Exploitable via ``uploadify.php``.
|
| CVE-2015-10138 |
|
Unrestricted File Upload in wordpress (CVE-2015-10138)
vulnerability in wordpress (CVE-2015-10138). Successful exploitation can lead to full system takeover.
|
| CVE-2024-5647 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2024-5647)
cross-site scripting in wordpress (CVE-2024-5647). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-4334 |
|
Privilege Escalation in wordpress (CVE-2025-4334)
vulnerability in wordpress (CVE-2025-4334). Successful exploitation can lead to full system takeover.
|
| CVE-2022-50014 |
|
Vulnerability in wordpress (CVE-2022-50014)
vulnerability in wordpress (CVE-2022-50014). Successful exploitation can lead to full system takeover.
|
| CVE-2025-31692 |
|
OS Command Injection in drupal (CVE-2025-31692)
OS command injection in drupal (CVE-2025-31692). Successful exploitation can lead to full system takeover.
|
| CVE-2025-31693 |
|
OS Command Injection in drupal (CVE-2025-31693)
OS command injection in drupal (CVE-2025-31693). Successful exploitation can lead to full system takeover.
|
| CVE-2024-13461 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2024-13461)
cross-site scripting in wordpress (CVE-2024-13461). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-13272 |
|
Vulnerability in drupal (CVE-2024-13272)
vulnerability in drupal (CVE-2024-13272). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-49604 |
|
Vulnerability in wordpress (CVE-2024-49604)
vulnerability in wordpress (CVE-2024-49604). Successful exploitation can lead to full system takeover.
|
| CVE-2024-3822 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2024-3822)
cross-site scripting in wordpress (CVE-2024-3822). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-3823 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2024-3823)
vulnerability in wordpress (CVE-2024-3823). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-3824 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2024-3824)
vulnerability in wordpress (CVE-2024-3824). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-1310 |
|
Vulnerability in wordpress (CVE-2024-1310)
vulnerability in wordpress (CVE-2024-1310). Confidential information can be exposed externally.
|
| CVE-2024-0829 |
|
Vulnerability in c (CVE-2024-0829)
vulnerability in c (CVE-2024-0829). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-0830 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2024-0830)
vulnerability in wordpress (CVE-2024-0830). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-1282 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2024-1282)
cross-site scripting in wordpress (CVE-2024-1282). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-7070 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2023-7070)
cross-site scripting in wordpress (CVE-2023-7070). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-23752 KEV |
|
[KEV] Vulnerability in Joomla! joomla (CVE-2023-23752)
vulnerability in Joomla! joomla (CVE-2023-23752). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-3907 |
|
Vulnerability in wordpress (CVE-2022-3907)
vulnerability in wordpress (CVE-2022-3907). Confidential information can be exposed externally.
|
| CVE-2022-2356 |
|
Unrestricted File Upload in wordpress (CVE-2022-2356)
vulnerability in wordpress (CVE-2022-2356). Successful exploitation can lead to full system takeover.
|
| CVE-2022-32114 |
|
Unrestricted File Upload in strapi (CVE-2022-32114)
vulnerability in strapi (CVE-2022-32114). Successful exploitation can lead to full system takeover.
|
| CVE-2019-10869 |
|
Path Traversal in wordpress (CVE-2019-10869)
path traversal in wordpress (CVE-2019-10869). Successful exploitation can lead to full system takeover.
|
| CVE-2018-7602 KEV |
|
[KEV] Code Injection in Drupal core (CVE-2018-7602)
code injection in Drupal core (CVE-2018-7602). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-28397 |
|
Unrestricted File Upload in ghost (CVE-2022-28397)
vulnerability in ghost (CVE-2022-28397). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.42.1` or later.
|
| CVE-2019-6340 KEV |
|
[KEV] Unsafe Deserialization in Drupal core (CVE-2019-6340)
vulnerability in Drupal core (CVE-2019-6340). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-13671 KEV |
|
[KEV] Unrestricted File Upload in drupal (CVE-2020-13671)
vulnerability in drupal (CVE-2020-13671). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-24713 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2021-24713)
cross-site scripting in wordpress (CVE-2021-24713). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-41164 |
|
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The...
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result i...
|
| CVE-2020-25213 KEV |
|
[KEV] Unrestricted File Upload in Wordpress file-manager-plugin (CVE-2020-25213)
vulnerability in Wordpress file-manager-plugin (CVE-2020-25213). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-11738 KEV |
|
[KEV] Path Traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738)
path traversal in Wordpress snap-creek-duplicator-plugin (CVE-2020-11738). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-9978 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Wordpress social-warfare-plugin (CVE-2019-9978)
cross-site scripting in Wordpress social-warfare-plugin (CVE-2019-9978). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2018-7600 KEV |
|
[KEV] Vulnerability in drupal (CVE-2018-7600)
vulnerability in drupal (CVE-2018-7600). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-41182 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41182)
cross-site scripting in jqueryui (CVE-2021-41182). Data can be tampered with by attackers. Exploitable via ``altField``.
|
| CVE-2021-41183 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-41183)
cross-site scripting in c (CVE-2021-41183). Data can be tampered with by attackers.
|
| CVE-2021-41184 |
|
Cross-Site Scripting (XSS) in jqueryui (CVE-2021-41184)
cross-site scripting in jqueryui (CVE-2021-41184). Data can be tampered with by attackers.
|
| CVE-2020-28707 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2020-28707)
cross-site scripting in wordpress (CVE-2020-28707). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-9281 |
|
Cross-Site Scripting (XSS) in ckeditor (CVE-2020-9281)
cross-site scripting in ckeditor (CVE-2020-9281). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-10704 |
|
Cross-Site Scripting (XSS) in magento (CVE-2016-10704)
cross-site scripting in magento (CVE-2016-10704). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-3302 |
|
Vulnerability in wordpress (CVE-2015-3302)
vulnerability in wordpress (CVE-2015-3302). Confidential information can be exposed externally.
|
| CVE-2015-7666 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2015-7666)
cross-site scripting in wordpress (CVE-2015-7666). Risk of unauthorized operations or information disclosure.
|
| CVE-2015-7667 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2015-7667)
cross-site scripting in wordpress (CVE-2015-7667). Risk of unauthorized operations or information disclosure.
|