Total CVEs

150,049

Critical Severity

4,925

High Severity

17,421

Last 7 Days

1,814
Quick preset (or use dates below)
Clear Filters
Showing 741 - 760 of 150,049 CVEs
CVE-2026-14190 MEDIUM - 6.1

The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyon...

Vendor: Unknown
Product: Sina Extension for Elementor
Published: Jul 27, 2026
Source: NVD

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to perform SQL injection that executes when a visitor triggers a search.

Vendor: Unknown
Product: WPBot
Published: Jul 27, 2026
Source: NVD
CVE-2026-13726 HIGH - 7.1

The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against a victim who is induced to send a crafted request.

Vendor: Unknown
Product: MPG
Published: Jul 27, 2026
Source: NVD
CVE-2026-13714 CRITICAL - 9.8

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations...

Vendor: Unknown
Product: Realtyna Organic IDX plugin + WPL Real Estate
Published: Jul 27, 2026
Source: NVD
CVE-2026-13597 CRITICAL - 9.1

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the log...

Vendor: Unknown
Product: 微信二维码登陆
Published: Jul 27, 2026
Source: NVD
CVE-2026-13400 MEDIUM - 6.1

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Sc...

Vendor: Unknown
Product: Simply Schedule Appointments
Published: Jul 27, 2026
Source: NVD
CVE-2026-13390 MEDIUM - 5.3

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arb...

Vendor: Unknown
Product: The Events Calendar
Published: Jul 27, 2026
Source: NVD
CVE-2026-13332 CRITICAL - 9.1

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.

Vendor: Unknown
Product: Masteriyo LMS
Published: Jul 27, 2026
Source: NVD
CVE-2026-13152 HIGH - 8.1

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted ...

Vendor: Unknown
Product: Custom Fields Account Registration For Woocommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-12982 MEDIUM - 6.1

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.

Vendor: Unknown
Product: Document Gallery
Published: Jul 27, 2026
Source: NVD
CVE-2026-12493 HIGH - 7.5

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary o...

Vendor: Unknown
Product: Clover Payment Gateway by Zaytech for WooCommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-12394 CRITICAL - 9.8

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

Vendor: Unknown
Product: MemberGlut
Published: Jul 27, 2026
Source: NVD
CVE-2026-12255 HIGH - 8.1

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that accoun...

Vendor: Unknown
Product: MainWP Child
Published: Jul 27, 2026
Source: NVD
CVE-2026-10082 MEDIUM - 6.1

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged us...

Vendor: Unknown
Product: Advanced Ads
Published: Jul 27, 2026
Source: NVD
CVE-2025-15662 HIGH - 8.6

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration f...

Vendor: Unknown
Product: Printcart Web to Print Product Designer for WooCommerce
Published: Jul 27, 2026
Source: NVD

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

Vendor: XMLRPC-C
Product: XMLRPC-C
Published: Jul 27, 2026
Source: NVD
CVE-2026-17501 MEDIUM - 5.3

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of resources. The attack may be initiated remotely. The pull reque...

Vendor: ggml-org
Product: llama.cpp
Published: Jul 27, 2026
Source: NVD
CVE-2026-17500 MEDIUM - 5.3

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Vendor: ggml-org
Product: llama.cpp
Published: Jul 27, 2026
Source: NVD
CVE-2026-57990 HIGH - 7.4

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-57989 HIGH - 7.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Published: Jul 26, 2026
Source: NVD