Tagged “cve.org”
CVEs tagged cve.org, newest first.
20161 CVEsRSS
CVE-2026-78124Low· 3.7strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
CVE-2026-62089High· 7.1WordPress Master Addons for Elementor plugin <= 3.2.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.
CVE-2026-52630Critical· 9.8SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php
CVE-2026-8778Critical· 9.8MIPL Grouped Checkout Fields for WooCommerce <= 1.2.2 - Unauthenticated Arbitrary File Upload
The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versio…
CVE-2026-62140Medium· 5.3WordPress Quiz And Survey Master plugin <= 11.2.5 - Insecure Direct Object References (IDOR) vulnerability
Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.
CVE-2026-62137Medium· 5.3WordPress bbPress plugin <= 2.6.14 - Sensitive Data Exposure vulnerability
Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.
CVE-2026-62135Medium· 5.3WordPress Booktics plugin <= 1.0.24 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.
CVE-2026-62132Medium· 5.3WordPress Masteriyo - LMS plugin <= 3.4.0 - Broken Access Control vulnerability
Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-62113Medium· 4.3WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability
Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.
CVE-2026-62110Medium· 6.5WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability
Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.
CVE-2026-62107High· 8.8WordPress Masteriyo - LMS plugin <= 3.4.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.
CVE-2026-62103Critical· 9.8WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
CVE-2026-18579High· 7.2WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escapin…
CVE-2026-11496Medium· 6.5Woo PDF Invoice Builder <= 2.0.8 - Authenticated (Subscriber+) Insecure Direct Object Reference to Sensitive Order Information Disclosure
The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX ha…
CVE-2024-12145Medium· 4.3BuddyPress <= 14.3.3 - Insecure Direct Object Reference to Notifications Deletion
The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes…
CVE-2026-89265Medium· 4.3PoCMoguBlog through 6.2 Missing Authorization on the Admin getPictureSortByUid Endpoint
MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office …
CVE-2026-89260High· 7.5PoCMoguBlog through 6.2 XML External Entity Injection in the Unauthenticated WeChat Callback Endpoint
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an u…
CVE-2026-89259Critical· 9.8Hugo is a static site generator
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --al…
CVE-2026-89254High· 8.7AVideo CustomizeUser Stored XSS via field_name Parameter
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject …
CVE-2026-89249High· 8.7AVideo YPTWallet Stored XSS via CryptoWallet Configuration
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in…
CVE-2026-89244Medium· 6.1WWBN AVideo Reflected XSS via Gallery Category getBackURL
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href…
CVE-2026-89239Medium· 6.1WWBN AVideo Reflected XSS via Referer Header Comment Breakout
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding…
CVE-2026-89060High· 7.7A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
CVE-2026-6642Medium· 6.4Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import
The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset fi…
CVE-2026-62136Medium· 5.3WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.
CVE-2026-62114Medium· 5.3WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.
CVE-2026-62109High· 7.6WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability
Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.
CVE-2026-62102High· 8.8WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
CVE-2026-62088Medium· 5.3WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.
CVE-2026-19991High· 8.1UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion
The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from…