Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,985
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,901 - 1,920 of 34,868 CVEs
CVE-2016-20083 MEDIUM - 5.3

WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes o...

Vendor: henrikmelin
Product: More Fields
Published: Jun 15, 2026
Source: NVD
CVE-2016-20082 MEDIUM - 6.2

WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and ...

Vendor: abtest
Product: Abtest
Published: Jun 15, 2026
Source: NVD
CVE-2016-20081 HIGH - 7.5

WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access ...

Vendor: Husain
Product: HB Audio Gallery Lite
Published: Jun 15, 2026
Source: NVD
CVE-2016-20080 MEDIUM - 6.2

WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrary files by manipulating the wp_abspath parameter. Attackers can supply path traversal sequences or remote URLs through the wp_ab...

Vendor: Brandfolder
Product: Brandfolder
Published: Jun 15, 2026
Source: NVD
CVE-2016-20079 MEDIUM - 6.2

WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway p...

Vendor: jamie
Product: Dharma Booking
Published: Jun 15, 2026
Source: NVD
CVE-2016-20078 MEDIUM - 6.2

WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url parameter. Attackers can supply directory traversal sequences in GET requests to pic.php to access sensitive files like wp-config.ph...

Vendor: Henrique Dias
Product: IMDb Profile Widget
Published: Jun 15, 2026
Source: NVD
CVE-2016-20077 MEDIUM - 6.2

WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient input validation in decode.php. Attackers can supply base64-encoded file paths in the 'id' parameter to the decode.php ...

Vendor: KaymeePhotography
Product: Photocart Link
Published: Jun 15, 2026
Source: NVD
CVE-2016-20076 HIGH - 7.5

WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tools.php. Attackers can exploit insufficient input validation us...

Vendor: ChrisHurst
Product: Simple Backup
Published: Jun 15, 2026
Source: NVD
CVE-2016-20075 HIGH - 8.8

WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Produ...

Vendor: Etoilewebdesign
Product: Ultimate Product Catalog
Published: Jun 15, 2026
Source: NVD
CVE-2016-20074 MEDIUM - 4.3

WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into submitting POST requests to the plugin settings page via lzcs_adm...

Vendor: leethompson
Product: Lazy Content Slider Plugin
Published: Jun 15, 2026
Source: NVD
CVE-2016-20073 HIGH - 8.2

Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to e...

Vendor: mattkaye
Product: Answer My Question
Published: Jun 15, 2026
Source: NVD
CVE-2016-20072 HIGH - 8.2

BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the uid parameter. Attackers can craft requests to pages using the plugin's shortcode with UNION-based SQ...

Vendor: bbsetheme
Product: BBS e-Franchise
Published: Jun 15, 2026
Source: NVD
CVE-2016-20071 HIGH - 8.2

The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads ...

Vendor: 404-redirection-manager
Product: 404 Redirection Manager
Published: Jun 15, 2026
Source: NVD
CVE-2016-20070 MEDIUM - 6.4

WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscri...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20069 HIGH - 8.2

WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to exec...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20068 HIGH - 8.2

WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpo...

Vendor: dwbooster
Product: Booking Calendar Contact Form
Published: Jun 15, 2026
Source: NVD
CVE-2016-20067 MEDIUM - 4.3

WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page while logged in.

Vendor: dwbooster
Product: CP Polls
Published: Jun 15, 2026
Source: NVD
CVE-2016-20066 HIGH - 7.2

WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary Ja...

Vendor: dwbooster
Product: CP Polls
Published: Jun 15, 2026
Source: NVD

Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution.  This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release ...

Published: Jun 15, 2026
Source: NVD

Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users via OAuth2/OIDC sign-in. AshAuthentication's OAuth2 and OIDC family strategies matched the local user by email address (an upsert on the email field, or a user-defined sign-...

Vendor: team-alembic
Product: ash_authentication
Published: Jun 15, 2026
Source: NVD