Search Results (4638 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65582 2 Liquidthemes, Wordpress 2 Ai Hub, Wordpress 2026-08-13 7.7 High
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
CVE-2026-28174 2 Arraytics, Wordpress 2 Wp Event Solution, Wordpress 2026-08-13 6.5 Medium
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-28170 2 Meril, Wordpress 2 Blog Floating Button, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
CVE-2026-28142 2 Shamalli, Wordpress 2 Web Directory Free, Wordpress 2026-08-13 9.3 Critical
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
CVE-2026-27544 2 Quarka, Wordpress 2 Qa Analytics, Wordpress 2026-08-13 10 Critical
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVE-2026-27543 2 Fluxbuilder, Wordpress 2 Mstore Api, Wordpress 2026-08-13 8.1 High
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
CVE-2026-27538 2 Wordpress, Wpdirectorykit 2 Wordpress, Wp Directory Kit 2026-08-13 7.5 High
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-27536 2 Pluginops, Wordpress 2 Mailchimp Subscribe Form, Wordpress 2026-08-13 7.1 High
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
CVE-2026-27535 2 Solacewp, Wordpress 2 Solace Extra, Wordpress 2026-08-13 7.1 High
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
CVE-2026-27380 2 Magepeopleteam, Wordpress 2 Car Rental Manager, Wordpress 2026-08-13 7.2 High
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
CVE-2026-19716 1 Maalfer 1 Pentestify 2026-08-13 N/A
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
CVE-2026-73616 1 Openremote 1 Openremote 2026-08-13 6.5 Medium
OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to other realms. Attackers with write:admin role in one realm can send DELETE requests to remove notifications from the master realm or other tenants without authorization checks.
CVE-2026-73488 1 Flowiseai 1 Flowise 2026-08-13 N/A
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks.
CVE-2026-73484 1 Flowiseai 1 Flowise 2026-08-13 N/A
Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem.
CVE-2026-59507 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-13 9.3 Critical
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
CVE-2026-59504 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-13 9.1 Critical
CWE-602: Client-Side Enforcement of Server-Side Security
CVE-2026-59503 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-13 9.1 Critical
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
CVE-2026-59502 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-13 5.3 Medium
CWE-203: Observable Discrepancy
CVE-2026-59501 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-13 8.2 High
CWE-284: Improper Access Control
CVE-2026-59500 1 Priority 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) 2026-08-13 10 Critical
CWE-287: Improper Authentication