Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2026-73634 Vulnerability in apache (CVE-2026-73634)
vulnerability in apache (CVE-2026-73634). Risk of unauthorized operations or information disclosure.
CVE-2026-12248 SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
CVE-2026-73632 Vulnerability in apache (CVE-2026-73632)
vulnerability in apache (CVE-2026-73632). Risk of unauthorized operations or information disclosure.
CVE-2026-73631 Vulnerability in apache (CVE-2026-73631)
vulnerability in apache (CVE-2026-73631). Risk of unauthorized operations or information disclosure.
CVE-2026-18438 Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
CVE-2026-16142 Vulnerability in wordpress (CVE-2026-16142)
vulnerability in wordpress (CVE-2026-16142). Successful exploitation can lead to full system takeover.
CVE-2026-15142 Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
CVE-2026-14279 The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
CVE-2026-15826 Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
CVE-2026-72159 Vulnerability in express (CVE-2026-72159)
vulnerability in express (CVE-2026-72159). Risk of unauthorized operations or information disclosure.
CVE-2026-14229 Vulnerability in wordpress (CVE-2026-14229)
vulnerability in wordpress (CVE-2026-14229). Risk of unauthorized operations or information disclosure.
CVE-2026-14230 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14230)
cross-site scripting in wordpress (CVE-2026-14230). Risk of unauthorized operations or information disclosure.
CVE-2026-16611 Information Disclosure in wordpress (CVE-2026-16611)
vulnerability in wordpress (CVE-2026-16611). Confidential information can be exposed externally.
CVE-2026-16541 Information Disclosure in wordpress (CVE-2026-16541)
vulnerability in wordpress (CVE-2026-16541). Confidential information can be exposed externally.
CVE-2026-18216 Authentication Bypass in wordpress (CVE-2026-18216)
authentication bypass in wordpress (CVE-2026-18216). Confidential information can be exposed externally.
CVE-2026-18807 Vulnerability in wordpress (CVE-2026-18807)
vulnerability in wordpress (CVE-2026-18807). Risk of unauthorized operations or information disclosure.
CVE-2026-18387 SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
CVE-2026-17090 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
CVE-2026-16145 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
CVE-2026-16146 SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
CVE-2026-16586 SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
CVE-2026-15993 SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
CVE-2026-16094 SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
CVE-2026-15948 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
CVE-2026-15453 SQL Injection in wordpress (CVE-2026-15453)
SQL injection in wordpress (CVE-2026-15453). Confidential information can be exposed externally.
CVE-2026-13360 Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
CVE-2026-8840 Vulnerability in wordpress (CVE-2026-8840)
vulnerability in wordpress (CVE-2026-8840). Risk of unauthorized operations or information disclosure.
CVE-2026-15001 Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
CVE-2026-15303 Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
CVE-2026-15162 SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
CVE-2026-15965 Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
CVE-2026-15341 Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
CVE-2026-15312 Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
CVE-2026-16080 SQL Injection in wordpress (CVE-2026-16080)
SQL injection in wordpress (CVE-2026-16080). Confidential information can be exposed externally.
CVE-2026-12128 Vulnerability in wordpress (CVE-2026-12128)
vulnerability in wordpress (CVE-2026-12128). Risk of unauthorized operations or information disclosure. Exploitable via ``cart_data``.
CVE-2026-14484 Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
CVE-2026-14433 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
CVE-2026-73683 Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
CVE-2026-12365 Use-After-Free in c (CVE-2026-12365)
vulnerability in c (CVE-2026-12365). Risk of unauthorized operations or information disclosure.
CVE-2026-73633 Vulnerability in apache (CVE-2026-73633)
vulnerability in apache (CVE-2026-73633). Risk of unauthorized operations or information disclosure.
CVE-2026-72830 Privilege Escalation in symfony (CVE-2026-72830)
vulnerability in symfony (CVE-2026-72830). Successful exploitation can lead to full system takeover.
CVE-2026-19794 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
CVE-2026-12743 SQL Injection in wordpress (CVE-2026-12743)
SQL injection in wordpress (CVE-2026-12743). Confidential information can be exposed externally.
CVE-2026-14290 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14290)
cross-site scripting in wordpress (CVE-2026-14290). Successful exploitation can lead to full system takeover.
CVE-2026-16810 SQL Injection in wordpress (CVE-2026-16810)
SQL injection in wordpress (CVE-2026-16810). Confidential information can be exposed externally.
CVE-2026-12949 Vulnerability in wordpress (CVE-2026-12949)
vulnerability in wordpress (CVE-2026-12949). Successful exploitation can lead to full system takeover.
CVE-2026-16739 Authentication Bypass in wordpress (CVE-2026-16739)
authentication bypass in wordpress (CVE-2026-16739). Data can be tampered with by attackers.
CVE-2026-15205 SQL Injection in wordpress (CVE-2026-15205)
SQL injection in wordpress (CVE-2026-15205). Confidential information can be exposed externally.
CVE-2026-18039 Privilege Escalation in wordpress (CVE-2026-18039)
vulnerability in wordpress (CVE-2026-18039). Successful exploitation can lead to full system takeover.
CVE-2025-10308 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2025-10308)
vulnerability in wordpress (CVE-2025-10308). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →