CVEs classified under CWE-26, newest first.
1 CVERSS
CVE-2026-15896
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to re…