Vulnerabilities (CVE)

Total 398795 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65543 2026-08-12 N/A 7.5 HIGH
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-28177 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-66695 2026-08-12 N/A 6.5 MEDIUM
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66664 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
CVE-2026-65545 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65577 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-66707 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
CVE-2026-66439 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-66692 2026-08-12 N/A 4.3 MEDIUM
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-28140 2026-08-12 N/A 7.5 HIGH
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
CVE-2026-28147 2026-08-12 N/A 5.4 MEDIUM
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15.
CVE-2026-65553 2026-08-12 N/A 10.0 CRITICAL
Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVE-2026-66678 2026-08-12 N/A 4.3 MEDIUM
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVE-2026-66690 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
CVE-2026-66709 2026-08-12 N/A 9.1 CRITICAL
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-65552 2026-08-12 N/A 9.8 CRITICAL
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVE-2026-66701 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
CVE-2026-66440 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
CVE-2026-61961 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-65513 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.