Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18402 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18402)
cross-site scripting in wordpress (CVE-2026-18402). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9767 |
|
SQL Injection in wordpress (CVE-2026-9767)
SQL injection in wordpress (CVE-2026-9767). Confidential information can be exposed externally.
|
| CVE-2026-19613 |
|
Information Disclosure in wordpress (CVE-2026-19613)
vulnerability in wordpress (CVE-2026-19613). Confidential information can be exposed externally.
|
| CVE-2026-19712 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19712)
cross-site scripting in wordpress (CVE-2026-19712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17582 |
|
SQL Injection in wordpress (CVE-2026-17582)
SQL injection in wordpress (CVE-2026-17582). Confidential information can be exposed externally.
|
| CVE-2026-19714 |
|
Authentication Bypass in wordpress (CVE-2026-19714)
authentication bypass in wordpress (CVE-2026-19714). Confidential information can be exposed externally.
|
| CVE-2026-18653 |
|
SQL Injection in wordpress (CVE-2026-18653)
SQL injection in wordpress (CVE-2026-18653). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19711 |
|
Vulnerability in wordpress (CVE-2026-19711)
vulnerability in wordpress (CVE-2026-19711). Data can be tampered with by attackers.
|
| CVE-2026-17581 |
|
Code Injection in wordpress (CVE-2026-17581)
code injection in wordpress (CVE-2026-17581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15790 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15790)
cross-site scripting in wordpress (CVE-2026-15790). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15384 |
|
Authentication Bypass in wordpress (CVE-2026-15384)
authentication bypass in wordpress (CVE-2026-15384). Data can be tampered with by attackers.
|
| CVE-2026-10035 |
|
Unsafe Deserialization in wordpress (CVE-2026-10035)
vulnerability in wordpress (CVE-2026-10035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15351 |
|
SQL Injection in wordpress (CVE-2026-15351)
SQL injection in wordpress (CVE-2026-15351). Confidential information can be exposed externally.
|
| CVE-2026-15604 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15604)
cross-site scripting in wordpress (CVE-2026-15604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16775 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16775)
cross-site scripting in wordpress (CVE-2026-16775). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16758 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16758)
cross-site scripting in wordpress (CVE-2026-16758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17533 |
|
Privilege Escalation in wordpress (CVE-2026-17533)
vulnerability in wordpress (CVE-2026-17533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17123 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17123)
SSRF in wordpress (CVE-2026-17123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16099 |
|
Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18432 |
|
Privilege Escalation in wordpress (CVE-2026-18432)
vulnerability in wordpress (CVE-2026-18432). Successful exploitation can lead to full system takeover. Exploitable via ``item_id``.
|
| CVE-2026-15345 |
|
Vulnerability in wordpress (CVE-2026-15345)
vulnerability in wordpress (CVE-2026-15345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16079 |
|
SQL Injection in wordpress (CVE-2026-16079)
SQL injection in wordpress (CVE-2026-16079). Confidential information can be exposed externally.
|
| CVE-2026-16098 |
|
Unrestricted File Upload in wordpress (CVE-2026-16098)
vulnerability in wordpress (CVE-2026-16098). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15963 |
|
SQL Injection in wordpress (CVE-2026-15963)
SQL injection in wordpress (CVE-2026-15963). Confidential information can be exposed externally.
|
| CVE-2026-15056 |
|
Path Traversal in wordpress (CVE-2026-15056)
path traversal in wordpress (CVE-2026-15056). Confidential information can be exposed externally.
|
| CVE-2026-15726 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15726)
cross-site scripting in wordpress (CVE-2026-15726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13712 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13712)
cross-site scripting in wordpress (CVE-2026-13712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15441 |
|
Vulnerability in wordpress (CVE-2026-15441)
vulnerability in wordpress (CVE-2026-15441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18385 |
|
Code Injection in wordpress (CVE-2026-18385)
code injection in wordpress (CVE-2026-18385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16779 |
|
Vulnerability in wordpress (CVE-2026-16779)
vulnerability in wordpress (CVE-2026-16779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15602 |
|
SQL Injection in wordpress (CVE-2026-15602)
SQL injection in wordpress (CVE-2026-15602). Confidential information can be exposed externally.
|
| CVE-2026-15066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15066)
cross-site scripting in wordpress (CVE-2026-15066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13358 |
|
Vulnerability in wordpress (CVE-2026-13358)
vulnerability in wordpress (CVE-2026-13358). Confidential information can be exposed externally.
|
| CVE-2026-12905 |
|
Vulnerability in wordpress (CVE-2026-12905)
vulnerability in wordpress (CVE-2026-12905). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15002 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15002)
cross-site scripting in wordpress (CVE-2026-15002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14524 |
|
Path Traversal in wordpress (CVE-2026-14524)
path traversal in wordpress (CVE-2026-14524). Data can be tampered with by attackers.
|
| CVE-2026-13167 |
|
Vulnerability in wordpress (CVE-2026-13167)
vulnerability in wordpress (CVE-2026-13167). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15009 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15009)
cross-site scripting in wordpress (CVE-2026-15009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14498 |
|
Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10005 |
|
Vulnerability in wordpress (CVE-2025-10005)
vulnerability in wordpress (CVE-2025-10005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11780 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11780)
cross-site scripting in wordpress (CVE-2026-11780). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12477 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12477)
cross-site scripting in wordpress (CVE-2026-12477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2487 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2487)
cross-site scripting in wordpress (CVE-2026-2487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18855 |
|
Path Traversal in wordpress (CVE-2026-18855)
path traversal in wordpress (CVE-2026-18855). Data can be tampered with by attackers.
|
| CVE-2026-19598 |
|
Authorization Flaw in wordpress (CVE-2026-19598)
vulnerability in wordpress (CVE-2026-19598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19896 |
|
Vulnerability in flask (CVE-2026-19896)
vulnerability in flask (CVE-2026-19896). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74564 |
|
Vulnerability in express (CVE-2026-74564)
vulnerability in express (CVE-2026-74564). Confidential information can be exposed externally.
|
| CVE-2026-12248 |
|
SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
|
| CVE-2026-73634 |
|
Vulnerability in apache (CVE-2026-73634)
vulnerability in apache (CVE-2026-73634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73635 |
|
Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
|