VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15873 CVEsRSS

CVE-2026-66631High· 7.6
1w ago

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

▾ TwilightMoreconvert Team · smart-wishlist-for-more-convertEPSS 0.38%via NVD
CVE-2026-66630High· 7.6
1w ago

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

▾ TwilightPublishPress · organize-seriesEPSS 0.38%via NVD
CVE-2026-66628High· 7.6
1w ago

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

▾ TwilightWP Lab · wp-lister-for-ebayEPSS 0.38%via NVD
CVE-2026-66626High· 7.6
1w ago

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

▾ TwilightSonal S Sinha · skt-addons-for-elementorEPSS 0.38%via NVD
CVE-2026-66625High· 7.6
1w ago

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

▾ TwilightWCVendors · wc-vendorsEPSS 0.38%via NVD
CVE-2026-66624High· 7.6
1w ago

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

▾ TwilightLudwig You · wpmastertoolkitEPSS 0.38%via NVD
CVE-2026-66619High· 7.6
1w ago

Administrator SQL Injection in Newsletters <= 4.18 versions.

Administrator SQL Injection in Newsletters <= 4.18 versions.

▾ TwilightTribulant Software · newsletters-liteEPSS 0.38%via NVD
CVE-2026-66618High· 7.6
1w ago

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

▾ TwilightFlipper Code · wp-google-map-pluginEPSS 0.38%via NVD
CVE-2026-66617Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

▾ SunlitPublishPress · organize-seriesEPSS 0.22%via NVD
CVE-2026-66608Medium· 6.4
1w ago

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

▾ SunlitUnlimited Elements · unlimited-elements-for-elementorEPSS 0.23%via NVD
CVE-2026-66580High· 8.5
1w ago

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

▾ TwilightRexTheme · best-woocommerce-feedEPSS 0.36%via NVD
CVE-2026-66579Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetElements For ElementorEPSS 0.22%via NVD
CVE-2026-66578Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

▾ SunlitProperty Hive · propertyhiveEPSS 0.22%via NVD
CVE-2026-66577Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetSearchEPSS 0.22%via NVD
CVE-2026-66576Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlocks For ElementorEPSS 0.22%via NVD
CVE-2026-66575Medium· 5.3
1w ago

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

▾ SunlitKingAddons.com · king-addonsEPSS 0.29%via NVD
CVE-2026-66574Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

▾ Sunlitbdthemes · bdthemes-element-pack-liteEPSS 0.22%via NVD
CVE-2026-66573Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetTabsEPSS 0.22%via NVD
CVE-2026-66572Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlogEPSS 0.22%via NVD
CVE-2026-66571High· 7.1
1w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

▾ TwilightGabe Livan · wp-asset-clean-upEPSS 0.13%via NVD
CVE-2026-62108Critical· 9.8
1w ago

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

▾ MidnightminiOrange · headless-single-sign-onEPSS 0.61%via NVD
CVE-2026-62104Critical· 10.0
1w ago

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

▾ Midnightsuperweby · migratico-liteEPSS 0.86%via NVD
CVE-2026-62101Critical· 9.8
1w ago

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

▾ MidnightChris Åkerfeldt Wendel · eduadmin-bookingEPSS 0.61%via NVD
CVE-2026-14850High· 8.8
1w ago

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users…

▾ TwilightMobiAPParc · MobiAPParcEPSS 0.29%via NVD
CVE-2026-82723Low· 1.8
1w ago

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.18%via NVD
CVE-2026-86522Medium· 6.3
1w ago

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.74%via NVD
CVE-2026-82760High· 8.2
1w ago

Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in…

Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in…

▾ Twilightteam-alembic · ash_authenticationEPSS 0.74%via NVD
CVE-2026-82759Low· 1.8
1w ago

Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. …

Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. …

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.14%via NVD
CVE-2026-82685High· 7.6
1w ago

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token …

▾ Twilightteam-alembic · ash_authenticationEPSS 0.66%via NVD
CVE-2026-81632High· 7.2
1w ago

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

▾ Twilightteam-alembic · ash_authentication_phoenixEPSS 0.21%via NVD
CVEs tagged “cve.org” — page 161 · VulnSea