Export limit exceeded: 50092 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (16026 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-16788 2 Livecomposer, Wordpress 2 Live Composer – Free Wordpress Website Builder, Wordpress 2026-09-01 6.4 Medium
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's shortcode-aware kses handling preserves the serialized shortcode body as a placeholder before content filtering runs, allowing attacker-controlled values such as view_all_link, main_heading_link_title, main_filter_title_all, and button_text to reach render-time sinks entirely unescaped.
CVE-2026-18488 2 Creativethemes, Wordpress 2 Blocksy Companion, Wordpress 2026-09-01 6.4 Medium
The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-75964 2 Cozmoslabs, Wordpress 2 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, Wordpress 2026-09-01 6.1 Medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload reaches administrators with the manage_options capability when they visit the Users > Unconfirmed Email Addresses list table and interact with row-action links, as the poisoned javascript: href is rendered verbatim into the page HTML by row_actions().
CVE-2026-19796 2 Webilia, Wordpress 2 Listdom: Ai-powered Business Directory With Classifieds Ads Listings, Wordpress 2026-09-01 7.2 High
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and including, 5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Listdom Pro add-on to be active and the 'Display Options Per Listing' displ setting to be enabled, both of which are non-default configurations.
CVE-2026-75965 2 Cozmoslabs, Wordpress 2 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor, Wordpress 2026-09-01 6.4 Medium
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the wppb_toolbox_shortcodes_settings[format-date] option to be set to 'yes' by an administrator for the shortcode to be active and the vulnerability to be exploitable.
CVE-2026-82229 2 Miniorange, Wordpress 2 Wordpress Social Login And Register, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
CVE-2026-82221 2 Metagauss, Wordpress 2 Registrationmagic, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
CVE-2026-81764 2 Acato, Wordpress 2 Email Essentials, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
CVE-2026-81298 2 Varunvairavanlc, Wordpress 2 Leadconnector, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
CVE-2026-81290 2 Icegram, Wordpress 2 Email Subscribers & Newsletters, Wordpress 2026-09-01 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
CVE-2026-24369 2 Theme-one, Wordpress 2 The Grid, Wordpress 2026-09-01 7.1 High
Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-24368 1 Wordpress 1 Wordpress 2026-09-01 5.3 Medium
Missing Authorization vulnerability in ThemeOne The Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-28191 2 Theme-one, Wordpress 2 The Grid, Wordpress 2026-09-01 8.8 High
Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0.
CVE-2026-75797 2 Ai Engine Project, Wordpress 2 Ai Engine, Wordpress 2026-09-01 7.7 High
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature to be enabled; otherwise the same issue is reachable by an administrator, which on multisite allows a non-super subsite administrator to read the network-shared configuration and its secrets.
CVE-2026-75798 2 Ai Engine Project, Wordpress 2 Ai Engine, Wordpress 2026-09-01 5.3 Medium
The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account.
CVE-2026-18431 2 Themefusion, Wordpress 3 Avada | Website Builder For Wordpress & Woocommerce, Fusion Builder, Wordpress 2026-09-01 9.8 Critical
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the server. This can be used to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. Successful exploitation requires both Avada and Fusion Builder to be installed and active, as well as certain administrator-authored content to be present.
CVE-2026-15990 2 Strategy11, Wordpress 2 Formidable Forms, Wordpress 2026-09-01 7.5 High
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires Formidable Forms Lite, Formidable Forms Pro, and Formidable Charts to be active and requires the wp-content/uploads/frm-charts/ directory to exist, normally after an image-format chart is rendered.
CVE-2026-19092 2 Tutorlms, Wordpress 2 Tutor Lms, Wordpress 2026-09-01 9.8 Critical
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
CVE-2026-82226 2 Tickera, Wordpress 2 Tickera, Wordpress 2026-09-01 9.8 Critical
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.
CVE-2026-81779 2 Silk Themes, Wordpress 2 Newspapers X, Wordpress 2026-09-01 10 Critical
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.