Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19069 |
|
Vulnerability in sqli (CVE-2026-19069)
vulnerability in sqli (CVE-2026-19069). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19070 |
|
Vulnerability in sqli (CVE-2026-19070)
vulnerability in sqli (CVE-2026-19070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19071 |
|
Vulnerability in sqli (CVE-2026-19071)
vulnerability in sqli (CVE-2026-19071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19068 |
|
Vulnerability in sqli (CVE-2026-19068)
vulnerability in sqli (CVE-2026-19068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19064 |
|
Vulnerability in CVE-2026-19064 (CVE-2026-19064)
vulnerability in CVE-2026-19064 (CVE-2026-19064). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19065 |
|
Vulnerability in CVE-2026-19065 (CVE-2026-19065)
vulnerability in CVE-2026-19065 (CVE-2026-19065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19066 |
|
Vulnerability in c (CVE-2026-19066)
vulnerability in c (CVE-2026-19066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11976 |
|
Vulnerability in CVE-2026-11976 (CVE-2026-11976)
vulnerability in CVE-2026-11976 (CVE-2026-11976). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67434 |
|
OS Command Injection in squizlabs/php_codesniffer (CVE-2026-67434)
OS command injection in squizlabs/php_codesniffer (CVE-2026-67434). Risk of unauthorized operations or information disclosure. Exploitable via ``Gitblame``. Mitigation: upgrade to `4.0.2` or later.
|
| CVE-2026-71488 |
|
Vulnerability in league/commonmark (CVE-2026-71488)
vulnerability in league/commonmark (CVE-2026-71488). Risk of unauthorized operations or information disclosure. Exploitable via ``CommonMarkConverter``. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2026-71478 |
|
Cross-Site Scripting (XSS) in league/commonmark (CVE-2026-71478)
cross-site scripting in league/commonmark (CVE-2026-71478). Risk of unauthorized operations or information disclosure. Exploitable via ``AttributesExtension``. Mitigation: upgrade to `2.7.0` or later.
|
| CVE-2026-71434 |
|
Unrestricted File Upload in statamic/cms (CVE-2026-71434)
vulnerability in statamic/cms (CVE-2026-71434). Risk of unauthorized operations or information disclosure. Exploitable via ``assets``. Mitigation: upgrade to `5.74.3` or later.
|
| CVE-2026-65575 |
|
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
|
| CVE-2026-65576 |
|
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
|
| CVE-2026-65577 |
|
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
|
| CVE-2026-65578 |
|
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
|
| CVE-2026-65581 |
|
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
|
| CVE-2026-65579 |
|
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
|
| CVE-2026-65574 |
|
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
|
| CVE-2026-65573 |
|
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
|
| CVE-2026-65572 |
|
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
|
| CVE-2026-65571 |
|
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
|
| CVE-2026-65552 |
|
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
|
| CVE-2026-65556 |
|
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
|
| CVE-2026-65549 |
|
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
|
| CVE-2026-32327 |
|
Vulnerability in apache (CVE-2026-32327)
vulnerability in apache (CVE-2026-32327). Confidential information can be exposed externally.
|
| CVE-2026-34501 |
|
Vulnerability in apache (CVE-2026-34501)
vulnerability in apache (CVE-2026-34501). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34191 |
|
SQL Injection in apache (CVE-2026-34191)
SQL injection in apache (CVE-2026-34191). Confidential information can be exposed externally.
|
| CVE-2026-34502 |
|
Vulnerability in apache (CVE-2026-34502)
vulnerability in apache (CVE-2026-34502). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28139 |
|
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
|
| CVE-2025-49506 |
|
Vulnerability in apache (CVE-2025-49506)
vulnerability in apache (CVE-2025-49506). Confidential information can be exposed externally.
|
| CVE-2026-68079 |
|
Vulnerability in apache (CVE-2026-68079)
vulnerability in apache (CVE-2026-68079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61466 |
|
Vulnerability in apache (CVE-2026-61466)
vulnerability in apache (CVE-2026-61466). Confidential information can be exposed externally. Exploitable via ``scope``.
|
| CVE-2026-68481 |
|
Vulnerability in apache (CVE-2026-68481)
vulnerability in apache (CVE-2026-68481). Confidential information can be exposed externally.
|
| CVE-2026-63687 |
|
Vulnerability in apache (CVE-2026-63687)
vulnerability in apache (CVE-2026-63687). Confidential information can be exposed externally.
|
| CVE-2026-57818 |
|
Vulnerability in apache (CVE-2026-57818)
vulnerability in apache (CVE-2026-57818). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65583 |
|
Vulnerability in apache (CVE-2026-65583)
vulnerability in apache (CVE-2026-65583). Confidential information can be exposed externally.
|
| CVE-2026-54225 |
|
Vulnerability in apache (CVE-2026-54225)
vulnerability in apache (CVE-2026-54225). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66909 |
|
Unsafe Deserialization in apache (CVE-2026-66909)
vulnerability in apache (CVE-2026-66909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64958 |
|
Vulnerability in apache (CVE-2026-64958)
vulnerability in apache (CVE-2026-64958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65432 |
|
XXE (XML External Entity) in apache (CVE-2026-65432)
vulnerability in apache (CVE-2026-65432). Confidential information can be exposed externally.
|
| CVE-2026-57819 |
|
Vulnerability in apache (CVE-2026-57819)
vulnerability in apache (CVE-2026-57819). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57817 |
|
Vulnerability in apache (CVE-2026-57817)
vulnerability in apache (CVE-2026-57817). Successful exploitation can lead to full system takeover. Exploitable via ``c_hash``.
|
| CVE-2026-64640 |
|
Authorization Flaw in apache (CVE-2026-64640)
vulnerability in apache (CVE-2026-64640). Confidential information can be exposed externally.
|
| CVE-2026-19021 |
|
Vulnerability in sqli (CVE-2026-19021)
vulnerability in sqli (CVE-2026-19021). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19020 |
|
Vulnerability in sqli (CVE-2026-19020)
vulnerability in sqli (CVE-2026-19020). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18325 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-16636 |
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
| CVE-2026-15991 |
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
| CVE-2026-18968 |
|
Cross-Site Scripting (XSS) in CVE-2026-18968 (CVE-2026-18968)
cross-site scripting in CVE-2026-18968 (CVE-2026-18968). Risk of unauthorized operations or information disclosure.
|