Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,675
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,221 - 5,240 of 35,133 CVEs
CVE-2026-9723 MEDIUM - 4.3

The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This makes it possible for unauthenticated attackers to modify the plugin&...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9722 MEDIUM - 4.3

The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the addOptionsPageFields function. This makes it possible for unauthenticated attackers to update the plugin's set...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9599 MEDIUM - 4.3

The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the admin_init function. This makes it possible for unauthenticated attackers to modify the plugin's settings, in...

Published: Jun 02, 2026
Source: NVD
CVE-2026-9234 MEDIUM - 4.3

The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action (handled by JtlConnectorAdmin::save()) and o...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8885 MEDIUM - 6.4

The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callout' shortcode in all versions up to, and including, 1.1.1. This is due to insufficient input sanitization and output escaping on the 'width' and 'alig...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8422 MEDIUM - 4.3

The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.01. This is due to missing or incorrect nonce validation on the 'remove-meta-boxes-per-user-role' page. This makes it possible for unauthenticated at...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4081 MEDIUM - 6.4

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color�...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4080 MEDIUM - 6.4

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_c...

Published: Jun 02, 2026
Source: NVD
CVE-2026-4071 MEDIUM - 4.3

The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing nonce validation in the birdseed_plugin_settings_page() function. The function processes the 'birdseed_token' GET parameter and saves it to the ...

Published: Jun 02, 2026
Source: NVD
CVE-2026-3620 MEDIUM - 4.4

The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in all versions up to, and including, 0.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Admini...

Published: Jun 02, 2026
Source: NVD
CVE-2026-3514 HIGH - 7.5

In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of URL path exemptions for health check probes. Specifically, the authentication middleware exempts any URL path ending with 'health' or 'ready' from authentication ...

Vendor: prefect
Product: prefect
Published: Jun 02, 2026
Source: NVD
CVE-2026-2425 MEDIUM - 6.1

The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' parameter in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

Published: Jun 02, 2026
Source: NVD
CVE-2026-2382 MEDIUM - 6.4

The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it...

Published: Jun 02, 2026
Source: NVD
CVE-2026-1784 HIGH - 8.8

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

Vendor: redhat
Product: openshift_container_platform
Published: Jun 02, 2026
Source: NVD
CVE-2026-1451 MEDIUM - 6.1

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Published: Jun 02, 2026
Source: NVD
CVE-2026-1450 MEDIUM - 6.1

The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Published: Jun 02, 2026
Source: NVD
CVE-2025-5085 MEDIUM - 5.5

The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜blogrole_linkโ€™ parameter in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level acces...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8293 HIGH - 7.5

The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing an attacker who knows a user's password to obtain a WordPress authentication session for that user without completing the em...

Published: Jun 02, 2026
Source: NVD
CVE-2026-8206 CRITICAL - 9.8

The Kirki โ€“ Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. Th...

Published: Jun 02, 2026
Source: NVD
CVE-2026-3198 MEDIUM - 6.5

MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGat...

Vendor: lfprojects
Product: mlflow
Published: Jun 02, 2026
Source: NVD