Search

Search Results (404445 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-62046 2 Themerex Group, Wordpress-extensions 2 Gutentype, Gutentype 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
CVE-2026-62045 2 Themerex Group, Wordpress-extensions 2 Booklovers, Booklovers 2026-10-11 9.8 Critical
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
CVE-2026-62044 2026-10-11 7.2 High
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
CVE-2026-62038 2026-10-11 7.3 High
Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
CVE-2026-62035 2026-10-11 6.3 Medium
Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions.
CVE-2026-62033 2026-10-11 7.6 High
Subscriber Settings Change in uListing <= 2.2.0 versions.
CVE-2026-62028 2026-10-11 5.4 Medium
Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Before After Image Comparison – Image comparison for WP: from n/a through 1.1.21.
CVE-2026-62025 2026-10-11 9 Critical
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions.
CVE-2026-62024 2026-10-11 9.9 Critical
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions.
CVE-2026-62022 2026-10-11 9.8 Critical
Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions.
CVE-2026-62021 2026-10-11 8.8 High
Subscriber PHP Object Injection in Angio <= 1.1.1 versions.
CVE-2026-5725 2026-10-11 6.1 Medium
The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2026-4791 2026-10-11 6.4 Medium
The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-42719 2026-10-11 9.8 Critical
Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions.
CVE-2026-42706 2026-10-11 7.5 High
Unauthenticated Broken Access Control in DK <= 3.2.1 versions.
CVE-2026-42705 2026-10-11 7.5 High
Unauthenticated Broken Access Control in Grand News <= 3.4 versions.
CVE-2026-42696 2026-10-11 10 Critical
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1.5.19 versions.
CVE-2026-40808 2026-10-11 6.5 Medium
Subscriber Broken Access Control in Jetpack VideoPress <= 3.6 versions.
CVE-2026-40805 2026-10-11 7.7 High
Subscriber Arbitrary File Deletion in PeepSo <= 9.0.5.4 versions.
CVE-2026-40802 2026-10-11 7.6 High
Subscriber Settings Change in Pubjet | پاب‌جت <= 5.4.8 versions.