Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5336 |
|
Information Disclosure in wordpress (CVE-2026-5336)
vulnerability in wordpress (CVE-2026-5336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16620 |
|
Vulnerability in wordpress (CVE-2026-16620)
vulnerability in wordpress (CVE-2026-16620). Data can be tampered with by attackers.
|
| CVE-2026-16619 |
|
Vulnerability in wordpress (CVE-2026-16619)
vulnerability in wordpress (CVE-2026-16619). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16067 |
|
Vulnerability in wordpress (CVE-2026-16067)
vulnerability in wordpress (CVE-2026-16067). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15256 |
|
Vulnerability in wordpress (CVE-2026-15256)
vulnerability in wordpress (CVE-2026-15256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15208 |
|
Vulnerability in wordpress (CVE-2026-15208)
vulnerability in wordpress (CVE-2026-15208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15152 |
|
Vulnerability in wordpress (CVE-2026-15152)
vulnerability in wordpress (CVE-2026-15152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15149 |
|
Vulnerability in wordpress (CVE-2026-15149)
vulnerability in wordpress (CVE-2026-15149). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15147 |
|
Vulnerability in wordpress (CVE-2026-15147)
vulnerability in wordpress (CVE-2026-15147). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14831 |
|
Vulnerability in wordpress (CVE-2026-14831)
vulnerability in wordpress (CVE-2026-14831). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14842 |
|
Vulnerability in wordpress (CVE-2026-14842)
vulnerability in wordpress (CVE-2026-14842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14936 |
|
Vulnerability in wordpress (CVE-2026-14936)
vulnerability in wordpress (CVE-2026-14936). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14225 |
|
Vulnerability in wordpress (CVE-2026-14225)
vulnerability in wordpress (CVE-2026-14225). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14306 |
|
Vulnerability in wordpress (CVE-2026-14306)
vulnerability in wordpress (CVE-2026-14306). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14812 |
|
Vulnerability in wordpress (CVE-2026-14812)
vulnerability in wordpress (CVE-2026-14812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12501 |
|
Vulnerability in wordpress (CVE-2026-12501)
vulnerability in wordpress (CVE-2026-12501). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12584 |
|
Vulnerability in wordpress (CVE-2026-12584)
vulnerability in wordpress (CVE-2026-12584). Data can be tampered with by attackers.
|
| CVE-2026-12901 |
|
Vulnerability in wordpress (CVE-2026-12901)
vulnerability in wordpress (CVE-2026-12901). Data can be tampered with by attackers.
|
| CVE-2026-13342 |
|
Vulnerability in wordpress (CVE-2026-13342)
vulnerability in wordpress (CVE-2026-13342). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13399 |
|
Vulnerability in wordpress (CVE-2026-13399)
vulnerability in wordpress (CVE-2026-13399). Data can be tampered with by attackers.
|
| CVE-2026-11361 |
|
Vulnerability in wordpress (CVE-2026-11361)
vulnerability in wordpress (CVE-2026-11361). Data can be tampered with by attackers.
|
| CVE-2026-10524 |
|
Vulnerability in wordpress (CVE-2026-10524)
vulnerability in wordpress (CVE-2026-10524). Data can be tampered with by attackers.
|
| CVE-2026-10599 |
|
Vulnerability in wordpress (CVE-2026-10599)
vulnerability in wordpress (CVE-2026-10599). Data can be tampered with by attackers.
|
| CVE-2025-15674 |
|
Authorization Flaw in wordpress (CVE-2025-15674)
vulnerability in wordpress (CVE-2025-15674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71435 |
|
Cross-Site Scripting (XSS) in statamic/cms (CVE-2026-71435)
cross-site scripting in statamic/cms (CVE-2026-71435). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.3` or later.
|
| CVE-2026-71434 |
|
Unrestricted File Upload in statamic/cms (CVE-2026-71434)
vulnerability in statamic/cms (CVE-2026-71434). Risk of unauthorized operations or information disclosure. Exploitable via ``assets``. Mitigation: upgrade to `5.74.3` or later.
|
| CVE-2026-64662 |
|
Vulnerability in statamic/cms (CVE-2026-64662)
vulnerability in statamic/cms (CVE-2026-64662). Confidential information can be exposed externally. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64663 |
|
Vulnerability in statamic/cms (CVE-2026-64663)
vulnerability in statamic/cms (CVE-2026-64663). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64665 |
|
Authentication Bypass in statamic/cms (CVE-2026-64665)
authentication bypass in statamic/cms (CVE-2026-64665). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64664 |
|
Information Disclosure in statamic/cms (CVE-2026-64664)
vulnerability in statamic/cms (CVE-2026-64664). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-53977 |
|
Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3430 |
|
SQL Injection in wordpress (CVE-2026-3430)
SQL injection in wordpress (CVE-2026-3430). Confidential information can be exposed externally.
|
| CVE-2026-66705 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
|
| CVE-2026-66447 |
|
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
|
| CVE-2026-32327 |
|
Vulnerability in apache (CVE-2026-32327)
vulnerability in apache (CVE-2026-32327). Confidential information can be exposed externally.
|
| CVE-2026-34191 |
|
SQL Injection in apache (CVE-2026-34191)
SQL injection in apache (CVE-2026-34191). Confidential information can be exposed externally.
|
| CVE-2026-34501 |
|
Vulnerability in apache (CVE-2026-34501)
vulnerability in apache (CVE-2026-34501). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34502 |
|
Vulnerability in apache (CVE-2026-34502)
vulnerability in apache (CVE-2026-34502). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15246 |
|
Vulnerability in wordpress (CVE-2026-15246)
vulnerability in wordpress (CVE-2026-15246). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-49506 |
|
Vulnerability in apache (CVE-2025-49506)
vulnerability in apache (CVE-2025-49506). Confidential information can be exposed externally.
|
| CVE-2026-18501 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18501)
cross-site scripting in wordpress (CVE-2026-18501). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0673 |
|
Vulnerability in wordpress (CVE-2026-0673)
vulnerability in wordpress (CVE-2026-0673). Risk of unauthorized operations or information disclosure. Exploitable via ``element_pack_contact_form``.
|
| CVE-2026-68481 |
|
Vulnerability in apache (CVE-2026-68481)
vulnerability in apache (CVE-2026-68481). Confidential information can be exposed externally.
|
| CVE-2026-61466 |
|
Vulnerability in apache (CVE-2026-61466)
vulnerability in apache (CVE-2026-61466). Confidential information can be exposed externally. Exploitable via ``scope``.
|
| CVE-2026-68079 |
|
Vulnerability in apache (CVE-2026-68079)
vulnerability in apache (CVE-2026-68079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65583 |
|
Vulnerability in apache (CVE-2026-65583)
vulnerability in apache (CVE-2026-65583). Confidential information can be exposed externally.
|
| CVE-2026-63687 |
|
Vulnerability in apache (CVE-2026-63687)
vulnerability in apache (CVE-2026-63687). Confidential information can be exposed externally.
|
| CVE-2026-57818 |
|
Vulnerability in apache (CVE-2026-57818)
vulnerability in apache (CVE-2026-57818). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5391 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5391)
cross-site scripting in wordpress (CVE-2026-5391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5158 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5158)
cross-site scripting in wordpress (CVE-2026-5158). Risk of unauthorized operations or information disclosure.
|