Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15786 |
|
Path Traversal in wordpress (CVE-2026-15786)
path traversal in wordpress (CVE-2026-15786). Confidential information can be exposed externally.
|
| CVE-2026-15646 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15646)
cross-site scripting in wordpress (CVE-2026-15646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13119 |
|
SQL Injection in wordpress (CVE-2026-13119)
SQL injection in wordpress (CVE-2026-13119). Confidential information can be exposed externally.
|
| CVE-2026-15015 |
|
Vulnerability in wordpress (CVE-2026-15015)
vulnerability in wordpress (CVE-2026-15015). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14481 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14481)
cross-site scripting in wordpress (CVE-2026-14481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13009 |
|
SQL Injection in wordpress (CVE-2026-13009)
SQL injection in wordpress (CVE-2026-13009). Confidential information can be exposed externally.
|
| CVE-2026-14282 |
|
Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15011 |
|
Code Injection in wordpress (CVE-2026-15011)
code injection in wordpress (CVE-2026-15011). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15394 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15394)
cross-site scripting in wordpress (CVE-2026-15394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15348 |
|
Authentication Bypass in wordpress (CVE-2026-15348)
authentication bypass in wordpress (CVE-2026-15348). Risk of unauthorized operations or information disclosure. Exploitable via ``wpdmppdl``.
|
| CVE-2026-15017 |
|
Privilege Escalation in wordpress (CVE-2026-15017)
vulnerability in wordpress (CVE-2026-15017). Successful exploitation can lead to full system takeover. Exploitable via ``new_role``.
|
| CVE-2026-9713 |
|
SQL Injection in wordpress (CVE-2026-9713)
SQL injection in wordpress (CVE-2026-9713). Confidential information can be exposed externally.
|
| CVE-2026-9729 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9729)
cross-site scripting in wordpress (CVE-2026-9729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9577 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9577)
cross-site scripting in wordpress (CVE-2026-9577). Risk of unauthorized operations or information disclosure. Exploitable via ``mod``.
|
| CVE-2026-12421 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12421)
cross-site scripting in wordpress (CVE-2026-12421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9635 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9635)
cross-site scripting in wordpress (CVE-2026-9635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9066)
cross-site scripting in wordpress (CVE-2026-9066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12082 |
|
Vulnerability in wordpress (CVE-2026-12082)
vulnerability in wordpress (CVE-2026-12082). Confidential information can be exposed externally.
|
| CVE-2026-14291 |
|
Authentication Bypass in wordpress (CVE-2026-14291)
authentication bypass in wordpress (CVE-2026-14291). Confidential information can be exposed externally.
|
| CVE-2026-7534 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7534)
cross-site scripting in wordpress (CVE-2026-7534). Risk of unauthorized operations or information disclosure. Exploitable via ``user_has_cap``.
|
| CVE-2026-7232 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7232)
cross-site scripting in wordpress (CVE-2026-7232). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13146 |
|
Code Injection in wordpress (CVE-2025-13146)
code injection in wordpress (CVE-2025-13146). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15787 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15787)
cross-site scripting in wordpress (CVE-2026-15787). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12968 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12968)
cross-site scripting in wordpress (CVE-2026-12968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14322 |
|
Vulnerability in wordpress (CVE-2026-14322)
vulnerability in wordpress (CVE-2026-14322). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12987 |
|
SQL Injection in wordpress (CVE-2026-12987)
SQL injection in wordpress (CVE-2026-12987). Confidential information can be exposed externally.
|
| CVE-2026-15802 |
|
Vulnerability in wordpress (CVE-2026-15802)
vulnerability in wordpress (CVE-2026-15802). Data can be tampered with by attackers.
|
| CVE-2026-47247 |
|
Information Disclosure in wordpress (CVE-2026-47247)
vulnerability in wordpress (CVE-2026-47247). Confidential information can be exposed externally.
|
| CVE-2026-65052 |
|
Vulnerability in wordpress (CVE-2026-65052)
vulnerability in wordpress (CVE-2026-65052). Data can be tampered with by attackers.
|
| CVE-2026-65051 |
|
Vulnerability in wordpress (CVE-2026-65051)
vulnerability in wordpress (CVE-2026-65051). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65050 |
|
Vulnerability in wordpress (CVE-2026-65050)
vulnerability in wordpress (CVE-2026-65050). Confidential information can be exposed externally. Exploitable via ``wp_localize_script``.
|
| CVE-2026-65048 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65048)
cross-site scripting in wordpress (CVE-2026-65048). Confidential information can be exposed externally.
|
| CVE-2026-65049 |
|
Authorization Flaw in wordpress (CVE-2026-65049)
vulnerability in wordpress (CVE-2026-65049). Data can be tampered with by attackers.
|
| CVE-2026-1771 |
|
Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1372 |
|
Vulnerability in wordpress (CVE-2026-1372)
vulnerability in wordpress (CVE-2026-1372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15145)
cross-site scripting in wordpress (CVE-2026-15145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8082 |
|
SQL Injection in wordpress (CVE-2026-8082)
SQL injection in wordpress (CVE-2026-8082). Confidential information can be exposed externally.
|
| CVE-2026-14185 |
|
Vulnerability in wordpress (CVE-2026-14185)
vulnerability in wordpress (CVE-2026-14185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14184 |
|
Vulnerability in wordpress (CVE-2026-14184)
vulnerability in wordpress (CVE-2026-14184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14183 |
|
Vulnerability in wordpress (CVE-2026-14183)
vulnerability in wordpress (CVE-2026-14183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13694 |
|
Vulnerability in c (CVE-2026-13694)
vulnerability in c (CVE-2026-13694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13693 |
|
Path Traversal in wordpress (CVE-2026-13693)
path traversal in wordpress (CVE-2026-13693). Confidential information can be exposed externally.
|
| CVE-2026-11767 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11767)
cross-site scripting in wordpress (CVE-2026-11767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13439 |
|
Privilege Escalation in wordpress (CVE-2026-13439)
vulnerability in wordpress (CVE-2026-13439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15782 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15782)
cross-site scripting in wordpress (CVE-2026-15782). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15156 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15156)
cross-site scripting in wordpress (CVE-2026-15156). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12900 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12900)
cross-site scripting in wordpress (CVE-2026-12900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9833 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9833)
cross-site scripting in wordpress (CVE-2026-9833). Risk of unauthorized operations or information disclosure. Exploitable via ``edit_pages``.
|
| CVE-2026-8825 |
|
Information Disclosure in wordpress (CVE-2026-8825)
vulnerability in wordpress (CVE-2026-8825). Confidential information can be exposed externally.
|
| CVE-2026-12970 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12970)
cross-site scripting in wordpress (CVE-2026-12970). Risk of unauthorized operations or information disclosure.
|