Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-16954 Information Disclosure in wordpress (CVE-2026-16954)
vulnerability in wordpress (CVE-2026-16954). Confidential information can be exposed externally.
CVE-2026-16734 Vulnerability in wordpress (CVE-2026-16734)
vulnerability in wordpress (CVE-2026-16734). Data can be tampered with by attackers.
CVE-2026-16537 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16537)
cross-site scripting in wordpress (CVE-2026-16537). Risk of unauthorized operations or information disclosure.
CVE-2026-16290 Vulnerability in wordpress (CVE-2026-16290)
vulnerability in wordpress (CVE-2026-16290). Risk of unauthorized operations or information disclosure.
CVE-2026-16268 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16268)
SSRF in wordpress (CVE-2026-16268). Data can be tampered with by attackers.
CVE-2026-16065 SQL Injection in wordpress (CVE-2026-16065)
SQL injection in wordpress (CVE-2026-16065). Confidential information can be exposed externally.
CVE-2026-16054 Vulnerability in wordpress (CVE-2026-16054)
vulnerability in wordpress (CVE-2026-16054). Data can be tampered with by attackers.
CVE-2026-14829 Vulnerability in wordpress (CVE-2026-14829)
vulnerability in wordpress (CVE-2026-14829). Data can be tampered with by attackers.
CVE-2026-14547 Authentication Bypass in wordpress (CVE-2026-14547)
authentication bypass in wordpress (CVE-2026-14547). Risk of unauthorized operations or information disclosure.
CVE-2026-14314 Information Disclosure in wordpress (CVE-2026-14314)
vulnerability in wordpress (CVE-2026-14314). Risk of unauthorized operations or information disclosure.
CVE-2026-14313 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-14313)
vulnerability in wordpress (CVE-2026-14313). Risk of unauthorized operations or information disclosure.
CVE-2026-14240 Information Disclosure in wordpress (CVE-2026-14240)
vulnerability in wordpress (CVE-2026-14240). Risk of unauthorized operations or information disclosure.
CVE-2026-14204 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-14204)
vulnerability in wordpress (CVE-2026-14204). Data can be tampered with by attackers.
CVE-2026-13703 Vulnerability in wordpress (CVE-2026-13703)
vulnerability in wordpress (CVE-2026-13703). Risk of unauthorized operations or information disclosure.
CVE-2026-13154 Information Disclosure in wordpress (CVE-2026-13154)
vulnerability in wordpress (CVE-2026-13154). Confidential information can be exposed externally.
CVE-2026-13153 Information Disclosure in wordpress (CVE-2026-13153)
vulnerability in wordpress (CVE-2026-13153). Confidential information can be exposed externally.
CVE-2026-12713 SQL Injection in wordpress (CVE-2026-12713)
SQL injection in wordpress (CVE-2026-12713). Confidential information can be exposed externally.
CVE-2026-11588 Cross-Site Scripting (XSS) in wordpress (CVE-2026-11588)
cross-site scripting in wordpress (CVE-2026-11588). Risk of unauthorized operations or information disclosure.
CVE-2025-15678 Cross-Site Scripting (XSS) in wordpress (CVE-2025-15678)
cross-site scripting in wordpress (CVE-2025-15678). Risk of unauthorized operations or information disclosure.
CVE-2026-18998 Vulnerability in CVE-2026-18998 (CVE-2026-18998)
vulnerability in CVE-2026-18998 (CVE-2026-18998). Risk of unauthorized operations or information disclosure.
CVE-2026-19000 SSRF (Server-Side Request Forgery) in CVE-2026-19000 (CVE-2026-19000)
SSRF in CVE-2026-19000 (CVE-2026-19000). Risk of unauthorized operations or information disclosure.
CVE-2026-15459 Authentication Bypass in wordpress (CVE-2026-15459)
authentication bypass in wordpress (CVE-2026-15459). Successful exploitation can lead to full system takeover.
CVE-2026-18997 Vulnerability in CVE-2026-18997 (CVE-2026-18997)
vulnerability in CVE-2026-18997 (CVE-2026-18997). Risk of unauthorized operations or information disclosure.
CVE-2026-18996 Vulnerability in CVE-2026-18996 (CVE-2026-18996)
vulnerability in CVE-2026-18996 (CVE-2026-18996). Risk of unauthorized operations or information disclosure.
CVE-2026-18995 Information Disclosure in CVE-2026-18995 (CVE-2026-18995)
vulnerability in CVE-2026-18995 (CVE-2026-18995). Risk of unauthorized operations or information disclosure.
CVE-2026-18993 Vulnerability in CVE-2026-18993 (CVE-2026-18993)
vulnerability in CVE-2026-18993 (CVE-2026-18993). Risk of unauthorized operations or information disclosure.
CVE-2026-18992 Vulnerability in CVE-2026-18992 (CVE-2026-18992)
vulnerability in CVE-2026-18992 (CVE-2026-18992). Risk of unauthorized operations or information disclosure.
CVE-2026-18909 Vulnerability in dos (CVE-2026-18909)
vulnerability in dos (CVE-2026-18909). Risk of unauthorized operations or information disclosure.
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
CVE-2026-18991 Path Traversal in path-traversal (CVE-2026-18991)
path traversal in path-traversal (CVE-2026-18991). Risk of unauthorized operations or information disclosure.
CVE-2026-18990 Authentication Bypass in CVE-2026-18990 (CVE-2026-18990)
authentication bypass in CVE-2026-18990 (CVE-2026-18990). Risk of unauthorized operations or information disclosure.
CVE-2026-18980 Vulnerability in CVE-2026-18980 (CVE-2026-18980)
vulnerability in CVE-2026-18980 (CVE-2026-18980). Risk of unauthorized operations or information disclosure.
CVE-2026-18976 Vulnerability in CVE-2026-18976 (CVE-2026-18976)
vulnerability in CVE-2026-18976 (CVE-2026-18976). Risk of unauthorized operations or information disclosure.
CVE-2026-18974 Information Disclosure in CVE-2026-18974 (CVE-2026-18974)
vulnerability in CVE-2026-18974 (CVE-2026-18974). Risk of unauthorized operations or information disclosure.
CVE-2026-18973 SSRF (Server-Side Request Forgery) in CVE-2026-18973 (CVE-2026-18973)
SSRF in CVE-2026-18973 (CVE-2026-18973). Risk of unauthorized operations or information disclosure.
CVE-2026-67872 Vulnerability in dos (CVE-2026-67872)
vulnerability in dos (CVE-2026-67872). Risk of unauthorized operations or information disclosure.
CVE-2026-67873 Vulnerability in c (CVE-2026-67873)
vulnerability in c (CVE-2026-67873). Successful exploitation can lead to full system takeover.
CVE-2026-52466 Authorization Flaw in CVE-2026-52466 (CVE-2026-52466)
vulnerability in CVE-2026-52466 (CVE-2026-52466). Successful exploitation can lead to full system takeover.
CVE-2026-19027 Out-of-Bounds Read in c (CVE-2026-19027)
vulnerability in c (CVE-2026-19027). Risk of unauthorized operations or information disclosure.
CVE-2026-67870 Vulnerability in CVE-2026-67870 (CVE-2026-67870)
vulnerability in CVE-2026-67870 (CVE-2026-67870). Successful exploitation can lead to full system takeover.
CVE-2026-67871 Vulnerability in c (CVE-2026-67871)
vulnerability in c (CVE-2026-67871). Risk of unauthorized operations or information disclosure.
CVE-2026-67869 Vulnerability in dos (CVE-2026-67869)
vulnerability in dos (CVE-2026-67869). Risk of unauthorized operations or information disclosure.
CVE-2023-54387 Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2023-54388 Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
CVE-2026-18968 Cross-Site Scripting (XSS) in CVE-2026-18968 (CVE-2026-18968)
cross-site scripting in CVE-2026-18968 (CVE-2026-18968). Risk of unauthorized operations or information disclosure.
CVE-2026-18970 Vulnerability in sqli (CVE-2026-18970)
vulnerability in sqli (CVE-2026-18970). Risk of unauthorized operations or information disclosure.
CVE-2026-19028 Out-of-Bounds Read in c (CVE-2026-19028)
vulnerability in c (CVE-2026-19028). Risk of unauthorized operations or information disclosure.
CVE-2026-18969 Vulnerability in CVE-2026-18969 (CVE-2026-18969)
vulnerability in CVE-2026-18969 (CVE-2026-18969). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →