Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19088 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-19088)
vulnerability in wordpress (CVE-2026-19088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48551 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-48551)
vulnerability in csrf (CVE-2026-48551). Data can be tampered with by attackers.
|
| CVE-2026-73292 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73292)
vulnerability in csrf (CVE-2026-73292). Confidential information can be exposed externally.
|
| CVE-2026-57858 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-57858)
cross-site scripting in csrf (CVE-2026-57858). Confidential information can be exposed externally.
|
| CVE-2026-73086 |
|
Vulnerability in csrf (CVE-2026-73086)
vulnerability in csrf (CVE-2026-73086). Confidential information can be exposed externally.
|
| CVE-2026-72778 |
|
Vulnerability in csrf (CVE-2026-72778)
vulnerability in csrf (CVE-2026-72778). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73162 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73162)
vulnerability in csrf (CVE-2026-73162). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72578 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-72578)
vulnerability in csrf (CVE-2026-72578). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66642 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66642)
vulnerability in csrf (CVE-2026-66642). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16965 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16965)
vulnerability in wordpress (CVE-2026-16965). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71850 |
|
Vulnerability in hono (CVE-2026-71850)
vulnerability in hono (CVE-2026-71850). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.34` or later.
|
| CVE-2026-16262 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16262)
vulnerability in wordpress (CVE-2026-16262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48085 |
|
Vulnerability in csrf (CVE-2026-48085)
vulnerability in csrf (CVE-2026-48085). Successful exploitation can lead to full system takeover. Exploitable via ``default``.
|
| CVE-2026-66686 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66686)
vulnerability in csrf (CVE-2026-66686). Data can be tampered with by attackers.
|
| CVE-2026-66681 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
|
| CVE-2026-28172 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
|
| CVE-2026-12605 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12605)
SSRF in ssrf (CVE-2026-12605). Successful exploitation can lead to full system takeover. Exploitable via ``gfresttoken``.
|
| CVE-2026-70556 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70556)
vulnerability in csrf (CVE-2026-70556). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-13394)
vulnerability in csrf (CVE-2025-13394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14204 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-14204)
vulnerability in wordpress (CVE-2026-14204). Data can be tampered with by attackers.
|
| CVE-2026-66885 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66885)
vulnerability in csrf (CVE-2026-66885). Confidential information can be exposed externally.
|
| CVE-2026-70434 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70434)
vulnerability in csrf (CVE-2026-70434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70432 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70432)
vulnerability in csrf (CVE-2026-70432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71273 |
|
Cross-Site Request Forgery (CSRF) in c (CVE-2026-71273)
vulnerability in c (CVE-2026-71273). Data can be tampered with by attackers. Exploitable via ``web_admin_password_enabled``.
|
| CVE-2026-71238 |
|
Vulnerability in django (CVE-2026-71238)
vulnerability in django (CVE-2026-71238). Confidential information can be exposed externally.
|
| CVE-2026-71239 |
|
Vulnerability in django (CVE-2026-71239)
vulnerability in django (CVE-2026-71239). Confidential information can be exposed externally.
|
| CVE-2026-7444 |
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
| CVE-2026-70376 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-5581 |
|
Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
|
| CVE-2026-11920 |
|
SQL Injection in wordpress (CVE-2026-11920)
SQL injection in wordpress (CVE-2026-11920). Confidential information can be exposed externally.
|
| CVE-2026-17515 |
|
Information Disclosure in wordpress (CVE-2026-17515)
vulnerability in wordpress (CVE-2026-17515). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18819 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-18819)
vulnerability in csrf (CVE-2026-18819). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66883 |
|
Vulnerability in csrf (CVE-2026-66883)
vulnerability in csrf (CVE-2026-66883). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67617 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-67617)
cross-site scripting in csrf (CVE-2026-67617). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/save_content_admin`.
|
| CVE-2026-69082 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-69082)
vulnerability in csrf (CVE-2026-69082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16292 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16292)
vulnerability in wordpress (CVE-2026-16292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12586 |
|
Authentication Bypass in wordpress (CVE-2026-12586)
authentication bypass in wordpress (CVE-2026-12586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15988 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15988)
vulnerability in wordpress (CVE-2026-15988). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13729 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-13729)
vulnerability in wordpress (CVE-2026-13729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50986 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-50986)
vulnerability in csrf (CVE-2026-50986). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67651 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-67651)
vulnerability in csrf (CVE-2025-67651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44613 |
|
Cross-Site Request Forgery (CSRF) in apache (CVE-2026-44613)
vulnerability in apache (CVE-2026-44613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28813 |
|
Cross-Site Request Forgery (CSRF) in apache (CVE-2026-28813)
vulnerability in apache (CVE-2026-28813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5219 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-5219)
vulnerability in csrf (CVE-2026-5219). Confidential information can be exposed externally.
|
| CVE-2026-14239 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14239)
cross-site scripting in wordpress (CVE-2026-14239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16729 |
|
Vulnerability in undici (CVE-2026-16729)
vulnerability in undici (CVE-2026-16729). Risk of unauthorized operations or information disclosure. Exploitable via ``setCookie``. Mitigation: upgrade to `8.9.0` or later.
|
| CVE-2026-65947 |
|
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
|
| CVE-2026-65944 |
|
Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
|
| CVE-2026-15344 |
|
SQL Injection in wordpress (CVE-2026-15344)
SQL injection in wordpress (CVE-2026-15344). Confidential information can be exposed externally.
|
| CVE-2026-63301 |
|
Vulnerability in csrf (CVE-2026-63301)
vulnerability in csrf (CVE-2026-63301). Risk of unauthorized operations or information disclosure.
|