Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12248 |
|
SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
|
| CVE-2026-73632 |
|
Vulnerability in apache (CVE-2026-73632)
vulnerability in apache (CVE-2026-73632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73631 |
|
Vulnerability in apache (CVE-2026-73631)
vulnerability in apache (CVE-2026-73631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16142 |
|
Vulnerability in wordpress (CVE-2026-16142)
vulnerability in wordpress (CVE-2026-16142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15142 |
|
Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-15826 |
|
Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72159 |
|
Vulnerability in express (CVE-2026-72159)
vulnerability in express (CVE-2026-72159). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14229 |
|
Vulnerability in wordpress (CVE-2026-14229)
vulnerability in wordpress (CVE-2026-14229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14230 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14230)
cross-site scripting in wordpress (CVE-2026-14230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16611 |
|
Information Disclosure in wordpress (CVE-2026-16611)
vulnerability in wordpress (CVE-2026-16611). Confidential information can be exposed externally.
|
| CVE-2026-16541 |
|
Information Disclosure in wordpress (CVE-2026-16541)
vulnerability in wordpress (CVE-2026-16541). Confidential information can be exposed externally.
|
| CVE-2026-18216 |
|
Authentication Bypass in wordpress (CVE-2026-18216)
authentication bypass in wordpress (CVE-2026-18216). Confidential information can be exposed externally.
|
| CVE-2026-18807 |
|
Vulnerability in wordpress (CVE-2026-18807)
vulnerability in wordpress (CVE-2026-18807). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18387 |
|
SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
|
| CVE-2026-17090 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16146 |
|
SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
|
| CVE-2026-16586 |
|
SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
|
| CVE-2026-15993 |
|
SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
|
| CVE-2026-16094 |
|
SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
|
| CVE-2026-15948 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15453 |
|
SQL Injection in wordpress (CVE-2026-15453)
SQL injection in wordpress (CVE-2026-15453). Confidential information can be exposed externally.
|
| CVE-2026-13360 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8840 |
|
Vulnerability in wordpress (CVE-2026-8840)
vulnerability in wordpress (CVE-2026-8840). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15001 |
|
Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
|
| CVE-2026-15303 |
|
Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15341 |
|
Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-15312 |
|
Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-16080 |
|
SQL Injection in wordpress (CVE-2026-16080)
SQL injection in wordpress (CVE-2026-16080). Confidential information can be exposed externally.
|
| CVE-2026-12128 |
|
Vulnerability in wordpress (CVE-2026-12128)
vulnerability in wordpress (CVE-2026-12128). Risk of unauthorized operations or information disclosure. Exploitable via ``cart_data``.
|
| CVE-2026-14484 |
|
Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
|
| CVE-2026-14433 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12365 |
|
Use-After-Free in c (CVE-2026-12365)
vulnerability in c (CVE-2026-12365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73633 |
|
Vulnerability in apache (CVE-2026-73633)
vulnerability in apache (CVE-2026-73633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72830 |
|
Privilege Escalation in symfony (CVE-2026-72830)
vulnerability in symfony (CVE-2026-72830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19794 |
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
| CVE-2026-12743 |
|
SQL Injection in wordpress (CVE-2026-12743)
SQL injection in wordpress (CVE-2026-12743). Confidential information can be exposed externally.
|
| CVE-2026-14290 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14290)
cross-site scripting in wordpress (CVE-2026-14290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16810 |
|
SQL Injection in wordpress (CVE-2026-16810)
SQL injection in wordpress (CVE-2026-16810). Confidential information can be exposed externally.
|
| CVE-2026-12949 |
|
Vulnerability in wordpress (CVE-2026-12949)
vulnerability in wordpress (CVE-2026-12949). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16739 |
|
Authentication Bypass in wordpress (CVE-2026-16739)
authentication bypass in wordpress (CVE-2026-16739). Data can be tampered with by attackers.
|
| CVE-2026-15205 |
|
SQL Injection in wordpress (CVE-2026-15205)
SQL injection in wordpress (CVE-2026-15205). Confidential information can be exposed externally.
|
| CVE-2026-18039 |
|
Privilege Escalation in wordpress (CVE-2026-18039)
vulnerability in wordpress (CVE-2026-18039). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10308 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2025-10308)
vulnerability in wordpress (CVE-2025-10308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18109 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18109)
cross-site scripting in wordpress (CVE-2026-18109). Risk of unauthorized operations or information disclosure.
|