Export limit exceeded: 400837 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400837 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-53953 | 2026-10-01 | 9.1 Critical | ||
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches. | ||||
| CVE-2026-103445 | 1 Wikimedia | 1 Mediawiki-page Forms Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-103437 | 1 Wikimedia | 1 Mediawiki-readinglists Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45. | ||||
| CVE-2026-103438 | 1 Wikimedia | 1 Mediawiki-wikistories Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-102397 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-10-01 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-94171 | 2 Villatheme, Wordpress-extensions | 2 Curcy, Curcy | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. | ||||
| CVE-2026-97256 | 2 Greg–siteorigin, Wordpress-extensions | 2 Page Builder By Siteorigin, Page Builder By Siteorigin | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | ||||
| CVE-2026-97265 | 2 Crocoblock. Jetimpex Inc., Wordpress-extensions | 2 Jetengine, Jetengine | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | ||||
| CVE-2026-97290 | 2 Sayontan Sinha, Wordpress-extensions | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Photonic Gallery & Lightbox For Flickr, Smugmug & Others | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | ||||
| CVE-2026-97291 | 2 Magazine3, Wordpress-extensions | 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | ||||
| CVE-2026-100510 | 2 Boldgrid, Wordpress-extensions | 2 Post And Page Builder, Post And Page Builder By Boldgrid | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | ||||
| CVE-2026-100512 | 2 Hook & Filter, Wordpress-extensions | 2 Nested Pages, Nested Pages | 2026-10-01 | 9.8 Critical |
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | ||||
| CVE-2026-102375 | 2 Optimole, Wordpress-extensions | 2 Optimole, Optimole | 2026-10-01 | 6.5 Medium |
| Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | ||||
| CVE-2026-102376 | 2 Wordpress-extensions, Wpmudev | 2 Branda, Branda | 2026-10-01 | 7.1 High |
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | ||||
| CVE-2026-102377 | 2 10web, Wordpress-extensions | 2 Photo Gallery, Photo Gallery By 10web | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | ||||
| CVE-2026-102391 | 2 Jetmonsters, Wordpress-extensions | 2 Jetformbuilder, Jetformbuilder | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | ||||
| CVE-2026-102392 | 2 Themehigh, Wordpress-extensions | 2 Extra Product Options For Woocommerce, Extra Product Options For Woocommerce | 2026-10-01 | 7.2 High |
| Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields <= 3.3.8 versions. | ||||
| CVE-2026-76142 | 1 Genians | 2 Genian Nac, Genian Ztna | 2026-10-01 | N/A |
| Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions | ||||
| CVE-2026-76143 | 1 Genians | 1 Genian Ssl Pns (frodo-core) | 2026-10-01 | N/A |
| A missing authorization vulnerability in Genian SSL PNS allows an attacker to bypass multi-factor authentication by manipulating a login request parameter. | ||||
| CVE-2026-76144 | 1 Genians | 2 Genian Ssl Pns (frodo-core), Genian Ssl Pns (watchcat-ui) | 2026-10-01 | N/A |
| An unrestricted file upload vulnerability caused by insufficient file extension and integrity verification in Genian SSL PNS allows an attacker to upload a dangerous file that is not an official patch | ||||