Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14603 |
|
Vulnerability in wordpress (CVE-2026-14603)
vulnerability in wordpress (CVE-2026-14603). Confidential information can be exposed externally.
|
| CVE-2026-12497 |
|
Privilege Escalation in wordpress (CVE-2026-12497)
vulnerability in wordpress (CVE-2026-12497). Confidential information can be exposed externally.
|
| CVE-2026-12688 |
|
Vulnerability in wordpress (CVE-2026-12688)
vulnerability in wordpress (CVE-2026-12688). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12689 |
|
Vulnerability in wordpress (CVE-2026-12689)
vulnerability in wordpress (CVE-2026-12689). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12690 |
|
Vulnerability in wordpress (CVE-2026-12690)
vulnerability in wordpress (CVE-2026-12690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12877 |
|
Authentication Bypass in wordpress (CVE-2026-12877)
authentication bypass in wordpress (CVE-2026-12877). Confidential information can be exposed externally.
|
| CVE-2026-12981 |
|
Privilege Escalation in wordpress (CVE-2026-12981)
vulnerability in wordpress (CVE-2026-12981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6454 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6454)
cross-site scripting in wordpress (CVE-2026-6454). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15420 |
|
Path Traversal in wordpress (CVE-2026-15420)
path traversal in wordpress (CVE-2026-15420). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15100 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15100)
cross-site scripting in wordpress (CVE-2026-15100). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13464 |
|
Vulnerability in wordpress (CVE-2026-13464)
vulnerability in wordpress (CVE-2026-13464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12736 |
|
Privilege Escalation in wordpress (CVE-2026-12736)
vulnerability in wordpress (CVE-2026-12736). Successful exploitation can lead to full system takeover. Exploitable via `POST /wp-json/wpify-woo/v1/option`.
|
| CVE-2026-11354 |
|
Vulnerability in wordpress (CVE-2026-11354)
vulnerability in wordpress (CVE-2026-11354). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9205 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-9205)
cross-site scripting in wordpress (CVE-2025-9205). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71389 |
|
Code Injection in react (CVE-2025-71389)
code injection in react (CVE-2025-71389). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58355 |
|
Vulnerability in react (CVE-2024-58355)
vulnerability in react (CVE-2024-58355). Confidential information can be exposed externally. Mitigation: upgrade to `4.7.16` or later.
|
| CVE-2024-58353 |
|
Vulnerability in react (CVE-2024-58353)
vulnerability in react (CVE-2024-58353). Confidential information can be exposed externally.
|
| CVE-2026-15981 |
|
Authentication Bypass in wordpress (CVE-2026-15981)
authentication bypass in wordpress (CVE-2026-15981). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15212 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15212)
vulnerability in wordpress (CVE-2026-15212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53669 |
|
Open Redirect in react-router (CVE-2026-53669)
vulnerability in react-router (CVE-2026-53669). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2026-53668 |
|
Cross-Site Scripting (XSS) in react-router-dom (CVE-2026-53668)
cross-site scripting in react-router-dom (CVE-2026-53668). Confidential information can be exposed externally. Mitigation: upgrade to `7.13.0` or later.
|
| CVE-2026-53667 |
|
Cross-Site Scripting (XSS) in react-router (CVE-2026-53667)
cross-site scripting in react-router (CVE-2026-53667). Confidential information can be exposed externally. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2026-53666 |
|
Vulnerability in react-router (CVE-2026-53666)
vulnerability in react-router (CVE-2026-53666). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.18.0` or later.
|
| CVE-2026-73421 |
|
Vulnerability in next-auth (CVE-2026-73421)
vulnerability in next-auth (CVE-2026-73421). Risk of unauthorized operations or information disclosure. Exploitable via ``auth``. Mitigation: upgrade to `5.0.0-beta.32` or later.
|
| CVE-2026-65522 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65522)
cross-site scripting in wordpress (CVE-2026-65522). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65500 |
|
Vulnerability in wordpress (CVE-2026-65500)
vulnerability in wordpress (CVE-2026-65500). Confidential information can be exposed externally.
|
| CVE-2026-65511 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65511)
cross-site scripting in wordpress (CVE-2026-65511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27377 |
|
Vulnerability in wordpress (CVE-2026-27377)
vulnerability in wordpress (CVE-2026-27377). Confidential information can be exposed externally.
|
| CVE-2025-68081 |
|
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
|
| CVE-2026-15906 |
|
SQL Injection in wordpress (CVE-2026-15906)
SQL injection in wordpress (CVE-2026-15906). Confidential information can be exposed externally.
|
| CVE-2026-15646 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15646)
cross-site scripting in wordpress (CVE-2026-15646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15786 |
|
Path Traversal in wordpress (CVE-2026-15786)
path traversal in wordpress (CVE-2026-15786). Confidential information can be exposed externally.
|
| CVE-2026-15794 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15794)
cross-site scripting in wordpress (CVE-2026-15794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15448 |
|
SQL Injection in wordpress (CVE-2026-15448)
SQL injection in wordpress (CVE-2026-15448). Confidential information can be exposed externally.
|
| CVE-2026-15647 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15647)
cross-site scripting in wordpress (CVE-2026-15647). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16078 |
|
Path Traversal in wordpress (CVE-2026-16078)
path traversal in wordpress (CVE-2026-16078). Confidential information can be exposed externally.
|
| CVE-2026-15827 |
|
Vulnerability in wordpress (CVE-2026-15827)
vulnerability in wordpress (CVE-2026-15827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15404 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15404)
cross-site scripting in wordpress (CVE-2026-15404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15761 |
|
SQL Injection in wordpress (CVE-2026-15761)
SQL injection in wordpress (CVE-2026-15761). Confidential information can be exposed externally.
|
| CVE-2026-15015 |
|
Vulnerability in wordpress (CVE-2026-15015)
vulnerability in wordpress (CVE-2026-15015). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15394 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15394)
cross-site scripting in wordpress (CVE-2026-15394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15348 |
|
Authentication Bypass in wordpress (CVE-2026-15348)
authentication bypass in wordpress (CVE-2026-15348). Risk of unauthorized operations or information disclosure. Exploitable via ``wpdmppdl``.
|
| CVE-2026-15017 |
|
Privilege Escalation in wordpress (CVE-2026-15017)
vulnerability in wordpress (CVE-2026-15017). Successful exploitation can lead to full system takeover. Exploitable via ``new_role``.
|
| CVE-2026-13119 |
|
SQL Injection in wordpress (CVE-2026-13119)
SQL injection in wordpress (CVE-2026-13119). Confidential information can be exposed externally.
|
| CVE-2026-14481 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14481)
cross-site scripting in wordpress (CVE-2026-14481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13009 |
|
SQL Injection in wordpress (CVE-2026-13009)
SQL injection in wordpress (CVE-2026-13009). Confidential information can be exposed externally.
|
| CVE-2026-14282 |
|
Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15011 |
|
Code Injection in wordpress (CVE-2026-15011)
code injection in wordpress (CVE-2026-15011). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9713 |
|
SQL Injection in wordpress (CVE-2026-9713)
SQL injection in wordpress (CVE-2026-9713). Confidential information can be exposed externally.
|
| CVE-2026-9729 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9729)
cross-site scripting in wordpress (CVE-2026-9729). Risk of unauthorized operations or information disclosure.
|