Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45045 |
|
Vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-45045)
vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-45045). Risk of unauthorized operations or information disclosure. Exploitable via ``BalancerForward``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-44332 |
|
Vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-44332)
vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-44332). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorizer``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-57685 |
|
Vulnerability in wordpress (CVE-2026-57685)
vulnerability in wordpress (CVE-2026-57685). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27402 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-27402)
cross-site scripting in wordpress (CVE-2026-27402). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69156 |
|
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
|
| CVE-2025-69155 |
|
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
|
| CVE-2025-69154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-69154)
cross-site scripting in wordpress (CVE-2025-69154). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69134 |
|
Vulnerability in wordpress (CVE-2025-69134)
vulnerability in wordpress (CVE-2025-69134). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69152 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-69152)
cross-site scripting in wordpress (CVE-2025-69152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9834 |
|
Command Injection in wordpress (CVE-2026-9834)
command injection in wordpress (CVE-2026-9834). Successful exploitation can lead to full system takeover. Exploitable via ``wp_db_exclude_table``.
|
| CVE-2026-9188 |
|
Vulnerability in wordpress (CVE-2026-9188)
vulnerability in wordpress (CVE-2026-9188). Risk of unauthorized operations or information disclosure. Exploitable via ``appointmentkey``.
|
| CVE-2026-9145 |
|
Path Traversal in wordpress (CVE-2026-9145)
path traversal in wordpress (CVE-2026-9145). Confidential information can be exposed externally.
|
| CVE-2026-8441 |
|
SQL Injection in wordpress (CVE-2026-8441)
SQL injection in wordpress (CVE-2026-8441). Confidential information can be exposed externally.
|
| CVE-2026-14029 |
|
SQL Injection in wordpress (CVE-2026-14029)
SQL injection in wordpress (CVE-2026-14029). Confidential information can be exposed externally.
|
| CVE-2026-13459 |
|
Vulnerability in wordpress (CVE-2026-13459)
vulnerability in wordpress (CVE-2026-13459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13369 |
|
Path Traversal in wordpress (CVE-2026-13369)
path traversal in wordpress (CVE-2026-13369). Confidential information can be exposed externally.
|
| CVE-2026-13252 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13252)
cross-site scripting in wordpress (CVE-2026-13252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13251 |
|
Path Traversal in wordpress (CVE-2026-13251)
path traversal in wordpress (CVE-2026-13251). Confidential information can be exposed externally.
|
| CVE-2026-12657 |
|
Vulnerability in wordpress (CVE-2026-12657)
vulnerability in wordpress (CVE-2026-12657). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12472 |
|
Vulnerability in wordpress (CVE-2026-12472)
vulnerability in wordpress (CVE-2026-12472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12134 |
|
Vulnerability in wordpress (CVE-2026-12134)
vulnerability in wordpress (CVE-2026-12134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12122 |
|
Vulnerability in wordpress (CVE-2026-12122)
vulnerability in wordpress (CVE-2026-12122). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11896 |
|
Vulnerability in wordpress (CVE-2026-11896)
vulnerability in wordpress (CVE-2026-11896). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10104 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10104)
cross-site scripting in wordpress (CVE-2026-10104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14249 |
|
Vulnerability in wordpress (CVE-2026-14249)
vulnerability in wordpress (CVE-2026-14249). Data can be tampered with by attackers.
|
| CVE-2026-5348 |
|
Vulnerability in wordpress (CVE-2026-5348)
vulnerability in wordpress (CVE-2026-5348). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13704 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13704)
cross-site scripting in wordpress (CVE-2026-13704). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11781 |
|
Vulnerability in wordpress (CVE-2026-11781)
vulnerability in wordpress (CVE-2026-11781). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11592 |
|
Vulnerability in wordpress (CVE-2026-11592)
vulnerability in wordpress (CVE-2026-11592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5821 |
|
Vulnerability in wordpress (CVE-2026-5821)
vulnerability in wordpress (CVE-2026-5821). Data can be tampered with by attackers.
|
| CVE-2026-11600 |
|
Vulnerability in wordpress (CVE-2026-11600)
vulnerability in wordpress (CVE-2026-11600). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11965 |
|
Vulnerability in wordpress (CVE-2026-11965)
vulnerability in wordpress (CVE-2026-11965). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13357 |
|
SQL Injection in wordpress (CVE-2026-13357)
SQL injection in wordpress (CVE-2026-13357). Confidential information can be exposed externally.
|
| CVE-2026-10089 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10089)
cross-site scripting in wordpress (CVE-2026-10089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10077 |
|
Vulnerability in wordpress (CVE-2026-10077)
vulnerability in wordpress (CVE-2026-10077). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11578 |
|
Vulnerability in wordpress (CVE-2026-11578)
vulnerability in wordpress (CVE-2026-11578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54259 |
|
Vulnerability in wagtail (CVE-2026-54259)
vulnerability in wagtail (CVE-2026-54259). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-54260 |
|
Vulnerability in wagtail (CVE-2026-54260)
vulnerability in wagtail (CVE-2026-54260). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-54261 |
|
Vulnerability in wagtail (CVE-2026-54261)
vulnerability in wagtail (CVE-2026-54261). Confidential information can be exposed externally. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-54262 |
|
Vulnerability in wagtail (CVE-2026-54262)
vulnerability in wagtail (CVE-2026-54262). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-54263 |
|
Cross-Site Scripting (XSS) in wagtail (CVE-2026-54263)
cross-site scripting in wagtail (CVE-2026-54263). Confidential information can be exposed externally. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-54164 |
|
Vulnerability in api-platform/core (CVE-2026-54164)
vulnerability in api-platform/core (CVE-2026-54164). Data can be tampered with by attackers. Exploitable via ``AbstractItemNormalizer``. Mitigation: upgrade to `4.3.12` or later.
|
| CVE-2026-49981 |
|
Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-54428 |
|
Vulnerability in org.apache.httpcomponents.core5:httpcore5-h2 (CVE-2026-54428)
vulnerability in org.apache.httpcomponents.core5:httpcore5-h2 (CVE-2026-54428). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5-beta2` or later.
|
| CVE-2026-54399 |
|
Vulnerability in org.apache.httpcomponents.core5:httpcore5 (CVE-2026-54399)
vulnerability in org.apache.httpcomponents.core5:httpcore5 (CVE-2026-54399). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5-beta2` or later.
|
| CVE-2026-58034 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-58034)
cross-site scripting in vue (CVE-2026-58034). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58035 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-58035)
cross-site scripting in vue (CVE-2026-58035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13228 |
|
Privilege Escalation in wordpress (CVE-2026-13228)
vulnerability in wordpress (CVE-2026-13228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12142 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12142)
cross-site scripting in wordpress (CVE-2026-12142). Risk of unauthorized operations or information disclosure.
|