Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13339 |
|
Path Traversal in wordpress (CVE-2026-13339)
path traversal in wordpress (CVE-2026-13339). Confidential information can be exposed externally.
|
| CVE-2026-18352 |
|
Path Traversal in wordpress (CVE-2026-18352)
path traversal in wordpress (CVE-2026-18352). Confidential information can be exposed externally.
|
| CVE-2026-16144 |
|
Code Injection in wordpress (CVE-2026-16144)
code injection in wordpress (CVE-2026-16144). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16635 |
|
Privilege Escalation in wordpress (CVE-2026-16635)
vulnerability in wordpress (CVE-2026-16635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15450 |
|
Path Traversal in wordpress (CVE-2026-15450)
path traversal in wordpress (CVE-2026-15450). Data can be tampered with by attackers.
|
| CVE-2026-15052 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15052)
cross-site scripting in wordpress (CVE-2026-15052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15988 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15988)
vulnerability in wordpress (CVE-2026-15988). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15244 |
|
Path Traversal in c (CVE-2026-15244)
path traversal in c (CVE-2026-15244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15368 |
|
Privilege Escalation in wordpress (CVE-2026-15368)
vulnerability in wordpress (CVE-2026-15368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14309 |
|
Authentication Bypass in wordpress (CVE-2026-14309)
authentication bypass in wordpress (CVE-2026-14309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14596 |
|
Authentication Bypass in wordpress (CVE-2026-14596)
authentication bypass in wordpress (CVE-2026-14596). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14836 |
|
Authentication Bypass in wordpress (CVE-2026-14836)
authentication bypass in wordpress (CVE-2026-14836). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14839 |
|
Information Disclosure in wordpress (CVE-2026-14839)
vulnerability in wordpress (CVE-2026-14839). Confidential information can be exposed externally.
|
| CVE-2026-13725 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13725)
cross-site scripting in wordpress (CVE-2026-13725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13158 |
|
Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13157 |
|
Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-62391 |
|
Path Traversal in apache (CVE-2026-62391)
path traversal in apache (CVE-2026-62391). Confidential information can be exposed externally.
|
| CVE-2026-16236 |
|
Unrestricted File Upload in wordpress (CVE-2026-16236)
vulnerability in wordpress (CVE-2026-16236). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15258 |
|
SQL Injection in wordpress (CVE-2026-15258)
SQL injection in wordpress (CVE-2026-15258). Confidential information can be exposed externally.
|
| CVE-2026-14930 |
|
Vulnerability in wordpress (CVE-2026-14930)
vulnerability in wordpress (CVE-2026-14930). Confidential information can be exposed externally.
|
| CVE-2026-15048 |
|
Information Disclosure in wordpress (CVE-2026-15048)
vulnerability in wordpress (CVE-2026-15048). Confidential information can be exposed externally.
|
| CVE-2026-14830 |
|
Authentication Bypass in wordpress (CVE-2026-14830)
authentication bypass in wordpress (CVE-2026-14830). Data can be tampered with by attackers.
|
| CVE-2026-14333 |
|
Privilege Escalation in wordpress (CVE-2026-14333)
vulnerability in wordpress (CVE-2026-14333). Confidential information can be exposed externally.
|
| CVE-2026-13609 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13609)
cross-site scripting in wordpress (CVE-2026-13609). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14319 |
|
Information Disclosure in wordpress (CVE-2026-14319)
vulnerability in wordpress (CVE-2026-14319). Confidential information can be exposed externally.
|
| CVE-2026-13392 |
|
Code Injection in wordpress (CVE-2026-13392)
code injection in wordpress (CVE-2026-13392). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12721 |
|
SQL Injection in wordpress (CVE-2026-12721)
SQL injection in wordpress (CVE-2026-12721). Confidential information can be exposed externally.
|
| CVE-2026-12720 |
|
Unsafe Deserialization in wordpress (CVE-2026-12720)
vulnerability in wordpress (CVE-2026-12720). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12695 |
|
Authentication Bypass in wordpress (CVE-2026-12695)
authentication bypass in wordpress (CVE-2026-12695). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12251 |
|
Privilege Escalation in wordpress (CVE-2026-12251)
vulnerability in wordpress (CVE-2026-12251). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66755 |
|
Path Traversal in apache (CVE-2026-66755)
path traversal in apache (CVE-2026-66755). Confidential information can be exposed externally.
|
| CVE-2026-66416 |
|
Cross-Site Request Forgery (CSRF) in laravel (CVE-2026-66416)
vulnerability in laravel (CVE-2026-66416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28813 |
|
Cross-Site Request Forgery (CSRF) in apache (CVE-2026-28813)
vulnerability in apache (CVE-2026-28813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28814 |
|
Vulnerability in apache (CVE-2026-28814)
vulnerability in apache (CVE-2026-28814). Confidential information can be exposed externally.
|
| CVE-2026-28811 |
|
Vulnerability in apache (CVE-2026-28811)
vulnerability in apache (CVE-2026-28811). Confidential information can be exposed externally.
|
| CVE-2026-15397 |
|
Vulnerability in wordpress (CVE-2026-15397)
vulnerability in wordpress (CVE-2026-15397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47858 |
|
Vulnerability in spring (CVE-2026-47858)
vulnerability in spring (CVE-2026-47858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47882 |
|
Vulnerability in spring (CVE-2026-47882)
vulnerability in spring (CVE-2026-47882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12687 |
|
Privilege Escalation in wordpress (CVE-2026-12687)
vulnerability in wordpress (CVE-2026-12687). Confidential information can be exposed externally.
|
| CVE-2026-15240 |
|
Authentication Bypass in c (CVE-2026-15240)
authentication bypass in c (CVE-2026-15240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13395 |
|
SQL Injection in wordpress (CVE-2026-13395)
SQL injection in wordpress (CVE-2026-13395). Confidential information can be exposed externally.
|
| CVE-2026-13178 |
|
Vulnerability in wordpress (CVE-2026-13178)
vulnerability in wordpress (CVE-2026-13178). Data can be tampered with by attackers.
|
| CVE-2026-14239 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14239)
cross-site scripting in wordpress (CVE-2026-14239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12500 |
|
Vulnerability in wordpress (CVE-2026-12500)
vulnerability in wordpress (CVE-2026-12500). Data can be tampered with by attackers.
|
| CVE-2026-14356 |
|
Vulnerability in wordpress (CVE-2026-14356)
vulnerability in wordpress (CVE-2026-14356). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1360 |
|
Unsafe Deserialization in wordpress (CVE-2026-1360)
vulnerability in wordpress (CVE-2026-1360). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
|
| CVE-2026-14270 |
|
Unrestricted File Upload in wordpress (CVE-2026-14270)
vulnerability in wordpress (CVE-2026-14270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16655 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16655)
cross-site scripting in wordpress (CVE-2026-16655). Risk of unauthorized operations or information disclosure. Exploitable via ``password``.
|