|
CVE-2026-66474
|
|
csrf に CSRF (CVE-2026-66474)
csrf に 脆弱性 (CVE-2026-66474) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
CSRF (クロスサイトリクエストフォージェリ)
Cwe 352
|
1ヶ月前
|
|
CVE-2026-66437
|
|
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.
|
Medium
|
SSRF (サーバーサイドリクエストフォージェリ)
Cwe 918
|
1ヶ月前
|
|
CVE-2026-65567
|
|
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
|
Medium
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-65563
|
|
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-66428
|
|
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
|
Medium
|
CSRF (クロスサイトリクエストフォージェリ)
Cwe 352
|
1ヶ月前
|
|
CVE-2026-65564
|
|
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
|
Medium
|
WordPress
Cwe 497
|
1ヶ月前
|
|
CVE-2026-66476
|
|
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.
|
Medium
|
CWE-22: パストラバーサル
|
1ヶ月前
|
|
CVE-2026-66475
|
|
CVE-2026-66475 に クロスサイトスクリプティング (CVE-2026-66475)
CVE-2026-66475 に XSS (クロスサイトスクリプティング) (CVE-2026-66475) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-66427
|
|
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-65436
|
|
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
|
Medium
|
CWE-22: パストラバーサル
|
1ヶ月前
|
|
CVE-2026-59558
|
|
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-59549
|
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
|
Critical
|
WordPress
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-59559
|
|
CVE-2026-59559 に クロスサイトスクリプティング (CVE-2026-59559)
CVE-2026-59559 に XSS (クロスサイトスクリプティング) (CVE-2026-59559) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-59552
|
|
ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-59552)
ssrf に SSRF (CVE-2026-59552) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
SSRF (サーバーサイドリクエストフォージェリ)
Cwe 918
|
1ヶ月前
|
|
CVE-2026-65435
|
|
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
|
Medium
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59550
|
|
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-59536
|
|
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
|
High
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-65557
|
|
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-59548
|
|
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
|
High
|
Cwe 497
|
1ヶ月前
|
|
CVE-2026-65561
|
|
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
|
Medium
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-59556
|
|
CVE-2026-59556 に クロスサイトスクリプティング (CVE-2026-59556)
CVE-2026-59556 に XSS (クロスサイトスクリプティング) (CVE-2026-59556) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-59560
|
|
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
|
Medium
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59551
|
|
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
|
High
|
WordPress
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-59537
|
|
sqli に SQLインジェクション (CVE-2026-59537)
sqli に SQLインジェクション (CVE-2026-59537) が存在。機密情報が外部に流出する可能性があります。
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-59553
|
|
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-59546
|
|
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
|
High
|
Cwe 639
|
1ヶ月前
|
|
CVE-2026-65434
|
|
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
|
Medium
|
Cwe 201
|
1ヶ月前
|
|
CVE-2026-59535
|
|
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
|
High
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59539
|
|
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
|
High
|
Cwe 639
|
1ヶ月前
|
|
CVE-2026-59532
|
|
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
|
High
|
Cwe 1284
|
1ヶ月前
|
|
CVE-2026-59533
|
|
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-65562
|
|
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1ヶ月前
|
|
CVE-2026-65433
|
|
CVE-2026-65433 の脆弱性 (CVE-2026-65433)
CVE-2026-65433 に 脆弱性 (CVE-2026-65433) が存在。データの不正な改ざんを許す可能性があります。
|
Medium
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59534
|
|
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
|
High
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59557
|
|
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
|
Medium
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59538
|
|
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2025-59180
|
|
CVE-2025-59180 の脆弱性 (CVE-2025-59180)
CVE-2025-59180 に 脆弱性 (CVE-2025-59180) が存在。不正な操作・情報露出のリスクがあります。
|
|
Cwe 798
|
1ヶ月前
|
|
CVE-2025-59181
|
|
path-traversal の脆弱性 (CVE-2025-59181)
path-traversal に 脆弱性 (CVE-2025-59181) が存在。不正な操作・情報露出のリスクがあります。
|
|
パストラバーサル
Cwe 35
|
1ヶ月前
|
|
CVE-2026-59527
|
|
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
|
Critical
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|
|
CVE-2026-10819
|
|
dos の脆弱性 (CVE-2026-10819)
dos に 脆弱性 (CVE-2026-10819) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
サービス拒否 (DoS)
Cwe 409
Mattermost
Mattermost Server
|
1ヶ月前
|
|
CVE-2026-59531
|
|
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
|
High
|
WordPress
Cwe 1284
|
1ヶ月前
|
|
CVE-2026-59529
|
|
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
|
High
|
Cwe 862
|
1ヶ月前
|
|
CVE-2026-59530
|
|
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
|
High
|
Cwe 862
|
1ヶ月前
|
|
CVE-2025-59178
|
|
CVE-2025-59178 の脆弱性 (CVE-2025-59178)
CVE-2025-59178 に 脆弱性 (CVE-2025-59178) が存在。不正な操作・情報露出のリスクがあります。
|
|
Cwe 497
|
1ヶ月前
|
|
CVE-2026-59528
|
|
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
|
High
|
Cwe 497
|
1ヶ月前
|
|
CVE-2026-10600
|
|
mattermost の脆弱性 (CVE-2026-10600)
mattermost に 脆弱性 (CVE-2026-10600) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
Cwe 770
Mattermost
Mattermost Server
|
1ヶ月前
|
|
CVE-2025-59177
|
|
CVE-2025-59177 の脆弱性 (CVE-2025-59177)
CVE-2025-59177 に 脆弱性 (CVE-2025-59177) が存在。不正な操作・情報露出のリスクがあります。
|
|
Cwe 209
|
1ヶ月前
|
|
CVE-2026-65878
|
|
CVE-2026-65878 に パストラバーサル (CVE-2026-65878)
CVE-2026-65878 に パストラバーサル (CVE-2026-65878) が存在。不正な操作・情報露出のリスクがあります。
|
|
CWE-22: パストラバーサル
|
1ヶ月前
|
|
CVE-2026-15003
|
|
c に 境界外読み取り (CVE-2026-15003)
c に 脆弱性 (CVE-2026-15003) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
C
サービス拒否 (DoS)
Cwe 125
|
1ヶ月前
|
|
CVE-2026-65877
|
|
sqli に SQLインジェクション (CVE-2026-65877)
sqli に SQLインジェクション (CVE-2026-65877) が存在。不正な操作・情報露出のリスクがあります。
|
|
SQLインジェクション
CWE-89: SQLインジェクション
|
1ヶ月前
|