Vulnerabilities (CVE)

Total 398795 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-32548 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
CVE-2026-65523 2026-08-12 N/A 7.5 HIGH
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
CVE-2026-28179 2026-08-12 N/A 5.9 MEDIUM
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-28082 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
CVE-2026-66683 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
CVE-2026-66684 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-66703 2026-08-12 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-28005 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVE-2026-61982 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-28146 2026-08-12 N/A 6.5 MEDIUM
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
CVE-2026-66706 2026-08-12 N/A 5.9 MEDIUM
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
CVE-2026-66470 2026-08-12 N/A 7.1 HIGH
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
CVE-2026-28139 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-65509 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-66425 2026-08-12 N/A 6.5 MEDIUM
Unauthenticated Broken Authentication in Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 versions.
CVE-2026-66699 2026-08-12 N/A 5.3 MEDIUM
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
CVE-2026-28178 2026-08-12 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-65573 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65560 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-66702 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.