|
CVE-2026-40775
|
|
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-42386
|
|
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-40767
|
|
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
|
High
|
Cwe 281
|
2ヶ月前
|
|
CVE-2026-40773
|
|
wordpress の脆弱性 (CVE-2026-40773)
wordpress に 脆弱性 (CVE-2026-40773) が存在。データの不正な改ざんを許す可能性があります。
|
Medium
|
WordPress
Cwe 862
|
2ヶ月前
|
|
CVE-2026-40798
|
|
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-40785
|
|
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
|
High
|
Cwe 288
|
2ヶ月前
|
|
CVE-2026-40781
|
|
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
|
High
|
Cwe 288
|
2ヶ月前
|
|
CVE-2026-40790
|
|
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
|
Medium
|
Cwe 288
|
2ヶ月前
|
|
CVE-2026-40782
|
|
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-40766
|
|
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-42381
|
|
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-40770
|
|
Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-40772
|
|
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
|
Critical
|
Cwe 434
|
2ヶ月前
|
|
CVE-2026-40771
|
|
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-40776
|
|
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-40762
|
|
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-40727
|
|
Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
|
High
|
CWE-22: パストラバーサル
|
2ヶ月前
|
|
CVE-2026-40743
|
|
Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39583
|
|
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
|
Critical
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-40741
|
|
Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.
Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39540
|
|
Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-39579
|
|
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
|
High
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-39532
|
|
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39594
|
|
Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.
Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39534
|
|
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39533
|
|
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39530
|
|
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-39584
|
|
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39502
|
|
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-40732
|
|
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-39527
|
|
Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.
Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.
|
Medium
|
Cwe 434
|
2ヶ月前
|
|
CVE-2026-39587
|
|
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
|
High
|
権限昇格
Cwe 266
|
2ヶ月前
|
|
CVE-2026-39591
|
|
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
|
Critical
|
WordPress
Cwe 434
|
2ヶ月前
|
|
CVE-2026-39524
|
|
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39525
|
|
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39513
|
|
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39498
|
|
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39519
|
|
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-39514
|
|
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-39507
|
|
Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-39503
|
|
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-39493
|
|
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-39499
|
|
CVE-2026-39499 に 安全でないデシリアライゼーション (CVE-2026-39499)
CVE-2026-39499 に 脆弱性 (CVE-2026-39499) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39512
|
|
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-39511
|
|
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2026-39481
|
|
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39472
|
|
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39478
|
|
CVE-2026-39478 に 安全でないデシリアライゼーション (CVE-2026-39478)
CVE-2026-39478 に 脆弱性 (CVE-2026-39478) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39471
|
|
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-39492
|
|
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|