Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2026-7529 Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
CVE-2026-7456 Vulnerability in wordpress (CVE-2026-7456)
vulnerability in wordpress (CVE-2026-7456). Data can be tampered with by attackers.
CVE-2026-17506 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-71241 Vulnerability in flask (CVE-2026-71241)
vulnerability in flask (CVE-2026-71241). Confidential information can be exposed externally.
CVE-2026-71239 Vulnerability in django (CVE-2026-71239)
vulnerability in django (CVE-2026-71239). Confidential information can be exposed externally.
CVE-2026-71238 Vulnerability in django (CVE-2026-71238)
vulnerability in django (CVE-2026-71238). Confidential information can be exposed externally.
CVE-2026-71233 Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
CVE-2026-15452 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15452)
cross-site scripting in wordpress (CVE-2026-15452). Risk of unauthorized operations or information disclosure.
CVE-2026-7726 Vulnerability in wordpress (CVE-2026-7726)
vulnerability in wordpress (CVE-2026-7726). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_handle_sync``.
CVE-2026-7693 Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-7441 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7441)
cross-site scripting in wordpress (CVE-2026-7441). Risk of unauthorized operations or information disclosure. Exploitable via ``posttype``.
CVE-2026-7105 Vulnerability in wordpress (CVE-2026-7105)
vulnerability in wordpress (CVE-2026-7105). Risk of unauthorized operations or information disclosure. Exploitable via ``xpro_content``.
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-6972 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6972)
cross-site scripting in wordpress (CVE-2026-6972). Risk of unauthorized operations or information disclosure. Exploitable via ``chart_size``.
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-6020 Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
CVE-2026-6079 Vulnerability in wordpress (CVE-2026-6079)
vulnerability in wordpress (CVE-2026-6079). Risk of unauthorized operations or information disclosure.
CVE-2026-61483 Vulnerability in apache (CVE-2026-61483)
vulnerability in apache (CVE-2026-61483). Risk of unauthorized operations or information disclosure.
CVE-2026-61484 Unsafe Deserialization in apache (CVE-2026-61484)
vulnerability in apache (CVE-2026-61484). Successful exploitation can lead to full system takeover.
CVE-2026-61485 Vulnerability in apache (CVE-2026-61485)
vulnerability in apache (CVE-2026-61485). Risk of unauthorized operations or information disclosure.
CVE-2026-61486 Vulnerability in apache (CVE-2026-61486)
vulnerability in apache (CVE-2026-61486). Successful exploitation can lead to full system takeover.
CVE-2026-5581 Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
CVE-2026-5651 SQL Injection in wordpress (CVE-2026-5651)
SQL injection in wordpress (CVE-2026-5651). Confidential information can be exposed externally.
CVE-2026-5108 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5108)
cross-site scripting in wordpress (CVE-2026-5108). Risk of unauthorized operations or information disclosure. Exploitable via ``innerHTML``.
CVE-2026-5116 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5116)
cross-site scripting in wordpress (CVE-2026-5116). Risk of unauthorized operations or information disclosure.
CVE-2026-4431 Vulnerability in wordpress (CVE-2026-4431)
vulnerability in wordpress (CVE-2026-4431). Data can be tampered with by attackers. Exploitable via ``rbsm_submit_post``.
CVE-2026-17532 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17532)
cross-site scripting in wordpress (CVE-2026-17532). Risk of unauthorized operations or information disclosure.
CVE-2026-18881 SQL Injection in wordpress (CVE-2026-18881)
SQL injection in wordpress (CVE-2026-18881). Confidential information can be exposed externally. Exploitable via ``tableon_get_table_data``.
CVE-2026-17505 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17505)
cross-site scripting in wordpress (CVE-2026-17505). Risk of unauthorized operations or information disclosure.
CVE-2026-15281 SQL Injection in wordpress (CVE-2026-15281)
SQL injection in wordpress (CVE-2026-15281). Confidential information can be exposed externally.
CVE-2026-12000 Vulnerability in wordpress (CVE-2026-12000)
vulnerability in wordpress (CVE-2026-12000). Confidential information can be exposed externally.
CVE-2026-11977 SQL Injection in wordpress (CVE-2026-11977)
SQL injection in wordpress (CVE-2026-11977). Confidential information can be exposed externally.
CVE-2026-11969 SQL Injection in wordpress (CVE-2026-11969)
SQL injection in wordpress (CVE-2026-11969). Confidential information can be exposed externally.
CVE-2026-11920 SQL Injection in wordpress (CVE-2026-11920)
SQL injection in wordpress (CVE-2026-11920). Confidential information can be exposed externally.
CVE-2026-11454 Vulnerability in wordpress (CVE-2026-11454)
vulnerability in wordpress (CVE-2026-11454). Confidential information can be exposed externally. Exploitable via `GET /wp-json/gh/v4/contacts/`.
CVE-2026-68078 Vulnerability in apache (CVE-2026-68078)
vulnerability in apache (CVE-2026-68078). Risk of unauthorized operations or information disclosure.
CVE-2026-68077 Vulnerability in apache (CVE-2026-68077)
vulnerability in apache (CVE-2026-68077). Risk of unauthorized operations or information disclosure.
CVE-2026-68075 Vulnerability in apache (CVE-2026-68075)
vulnerability in apache (CVE-2026-68075). Risk of unauthorized operations or information disclosure.
CVE-2026-68080 Vulnerability in apache (CVE-2026-68080)
vulnerability in apache (CVE-2026-68080). Risk of unauthorized operations or information disclosure.
CVE-2026-67555 Vulnerability in apache (CVE-2026-67555)
vulnerability in apache (CVE-2026-67555). Risk of unauthorized operations or information disclosure.
CVE-2026-67553 Vulnerability in apache (CVE-2026-67553)
vulnerability in apache (CVE-2026-67553). Risk of unauthorized operations or information disclosure.
CVE-2026-68073 Vulnerability in apache (CVE-2026-68073)
vulnerability in apache (CVE-2026-68073). Risk of unauthorized operations or information disclosure.
CVE-2026-67552 Vulnerability in apache (CVE-2026-67552)
vulnerability in apache (CVE-2026-67552). Risk of unauthorized operations or information disclosure.
CVE-2026-67590 Vulnerability in apache (CVE-2026-67590)
vulnerability in apache (CVE-2026-67590). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →