Search Results (43609 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-96828 2026-09-30 7.6 High
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
CVE-2026-96827 2026-09-30 7.6 High
Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
CVE-2026-96823 2026-09-30 7.5 High
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
CVE-2026-96822 2026-09-30 9.3 Critical
Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.
CVE-2026-96818 2026-09-30 7.5 High
Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.
CVE-2026-96817 2026-09-30 8.2 High
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
CVE-2026-96348 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
CVE-2026-96346 2026-09-30 7.6 High
Author SQL Injection in WP ERP <= 1.17.9 versions.
CVE-2026-96345 2026-09-30 7.6 High
Administrator SQL Injection in Estatik <= 4.3.5 versions.
CVE-2026-95587 2026-09-30 7.5 High
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
CVE-2026-94499 2026-09-30 7.1 High
Subscriber Broken Access Control in FormGent <= 1.12.2 versions.
CVE-2026-94177 2026-09-30 8.5 High
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
CVE-2026-94120 2026-09-30 7.5 High
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
CVE-2026-94115 2026-09-30 8.5 High
Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.
CVE-2026-94082 2026-09-30 7.6 High
Author SQL Injection in Quiz Cat <= 3.1.1 versions.
CVE-2026-94074 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-93621 2026-09-30 8.2 High
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-62085 2026-09-30 7.6 High
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
CVE-2026-27085 2026-09-30 2.7 Low
Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
CVE-2026-103117 1 Os4ed 1 Opensis-classic 2026-09-30 4.7 Medium
A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.