Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14516 |
|
SQL Injection in wordpress (CVE-2026-14516)
SQL injection in wordpress (CVE-2026-14516). Confidential information can be exposed externally.
|
| CVE-2026-12741 |
|
SQL Injection in wordpress (CVE-2026-12741)
SQL injection in wordpress (CVE-2026-12741). Confidential information can be exposed externally.
|
| CVE-2026-12800 |
|
SQL Injection in wordpress (CVE-2026-12800)
SQL injection in wordpress (CVE-2026-12800). Confidential information can be exposed externally. Exploitable via `POST /wp-json/wpdmpp/v1/cart/coupon`.
|
| CVE-2026-14870 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14870)
cross-site scripting in wordpress (CVE-2026-14870). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16585 |
|
Path Traversal in wordpress (CVE-2026-16585)
path traversal in wordpress (CVE-2026-16585). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14924 |
|
Vulnerability in wordpress (CVE-2026-14924)
vulnerability in wordpress (CVE-2026-14924). Data can be tampered with by attackers.
|
| CVE-2026-14490 |
|
Path Traversal in wordpress (CVE-2026-14490)
path traversal in wordpress (CVE-2026-14490). Confidential information can be exposed externally. Exploitable via ``demi_restore_step``.
|
| CVE-2026-65441 |
|
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
|
| CVE-2026-65442 |
|
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
|
| CVE-2026-65443 |
|
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
|
| CVE-2026-65446 |
|
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
|
| CVE-2026-65447 |
|
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
|
| CVE-2026-66473 |
|
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
|
| CVE-2026-61953 |
|
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
|
| CVE-2026-61957 |
|
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
|
| CVE-2026-65437 |
|
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
|
| CVE-2026-59551 |
|
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
|
| CVE-2026-59531 |
|
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
|
| CVE-2026-9830 |
|
Authentication Bypass in wordpress (CVE-2026-9830)
authentication bypass in wordpress (CVE-2026-9830). Confidential information can be exposed externally.
|
| CVE-2026-14235 |
|
Vulnerability in wordpress (CVE-2026-14235)
vulnerability in wordpress (CVE-2026-14235). Confidential information can be exposed externally.
|
| CVE-2026-13726 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13726)
cross-site scripting in wordpress (CVE-2026-13726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13152 |
|
Privilege Escalation in wordpress (CVE-2026-13152)
vulnerability in wordpress (CVE-2026-13152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12493 |
|
Authentication Bypass in wordpress (CVE-2026-12493)
authentication bypass in wordpress (CVE-2026-12493). Data can be tampered with by attackers.
|
| CVE-2026-12255 |
|
Authentication Bypass in wordpress (CVE-2026-12255)
authentication bypass in wordpress (CVE-2026-12255). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15662 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2025-15662)
SSRF in wordpress (CVE-2025-15662). Confidential information can be exposed externally.
|
| CVE-2026-15962 |
|
Unsafe Deserialization in wordpress (CVE-2026-15962)
vulnerability in wordpress (CVE-2026-15962). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10818 |
|
Unrestricted File Upload in wordpress (CVE-2026-10818)
vulnerability in wordpress (CVE-2026-10818). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8789 |
|
Authorization Flaw in wordpress (CVE-2026-8789)
vulnerability in wordpress (CVE-2026-8789). Data can be tampered with by attackers. Exploitable via ``ea_delete_multiple_connections``.
|
| CVE-2026-15401 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15401)
cross-site scripting in wordpress (CVE-2026-15401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10033 |
|
Vulnerability in wordpress (CVE-2026-10033)
vulnerability in wordpress (CVE-2026-10033). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14603 |
|
Vulnerability in wordpress (CVE-2026-14603)
vulnerability in wordpress (CVE-2026-14603). Confidential information can be exposed externally.
|
| CVE-2026-12981 |
|
Privilege Escalation in wordpress (CVE-2026-12981)
vulnerability in wordpress (CVE-2026-12981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12497 |
|
Privilege Escalation in wordpress (CVE-2026-12497)
vulnerability in wordpress (CVE-2026-12497). Confidential information can be exposed externally.
|
| CVE-2026-12736 |
|
Privilege Escalation in wordpress (CVE-2026-12736)
vulnerability in wordpress (CVE-2026-12736). Successful exploitation can lead to full system takeover. Exploitable via `POST /wp-json/wpify-woo/v1/option`.
|
| CVE-2026-15212 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15212)
vulnerability in wordpress (CVE-2026-15212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65511 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65511)
cross-site scripting in wordpress (CVE-2026-65511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65500 |
|
Vulnerability in wordpress (CVE-2026-65500)
vulnerability in wordpress (CVE-2026-65500). Confidential information can be exposed externally.
|
| CVE-2026-15017 |
|
Privilege Escalation in wordpress (CVE-2026-15017)
vulnerability in wordpress (CVE-2026-15017). Successful exploitation can lead to full system takeover. Exploitable via ``new_role``.
|
| CVE-2026-9713 |
|
SQL Injection in wordpress (CVE-2026-9713)
SQL injection in wordpress (CVE-2026-9713). Confidential information can be exposed externally.
|
| CVE-2026-12421 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12421)
cross-site scripting in wordpress (CVE-2026-12421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12082 |
|
Vulnerability in wordpress (CVE-2026-12082)
vulnerability in wordpress (CVE-2026-12082). Confidential information can be exposed externally.
|
| CVE-2026-14291 |
|
Authentication Bypass in wordpress (CVE-2026-14291)
authentication bypass in wordpress (CVE-2026-14291). Confidential information can be exposed externally.
|
| CVE-2026-7534 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7534)
cross-site scripting in wordpress (CVE-2026-7534). Risk of unauthorized operations or information disclosure. Exploitable via ``user_has_cap``.
|
| CVE-2026-7232 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7232)
cross-site scripting in wordpress (CVE-2026-7232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12968 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12968)
cross-site scripting in wordpress (CVE-2026-12968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12987 |
|
SQL Injection in wordpress (CVE-2026-12987)
SQL injection in wordpress (CVE-2026-12987). Confidential information can be exposed externally.
|
| CVE-2026-15802 |
|
Vulnerability in wordpress (CVE-2026-15802)
vulnerability in wordpress (CVE-2026-15802). Data can be tampered with by attackers.
|
| CVE-2026-47247 |
|
Information Disclosure in wordpress (CVE-2026-47247)
vulnerability in wordpress (CVE-2026-47247). Confidential information can be exposed externally.
|
| CVE-2026-65052 |
|
Vulnerability in wordpress (CVE-2026-65052)
vulnerability in wordpress (CVE-2026-65052). Data can be tampered with by attackers.
|
| CVE-2026-1771 |
|
Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
|