Tagged “nvd”
CVEs tagged nvd, newest first.
26765 CVEsRSS
CVE-2026-74000Medium· 5.3Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
CVE-2026-73999Medium· 5.4Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
CVE-2026-71568Medium· 5.3In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
CVE-2026-66676Medium· 5.3Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
CVE-2026-66631High· 7.6Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-66630High· 7.6Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
CVE-2026-66628High· 7.6Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
CVE-2026-66626High· 7.6Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
CVE-2026-66625High· 7.6Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
CVE-2026-66624High· 7.6Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
CVE-2026-66619High· 7.6Administrator SQL Injection in Newsletters <= 4.18 versions.
Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66618High· 7.6Administrator SQL Injection in WP Maps <= 4.9.9 versions.
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66617Medium· 6.5Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
CVE-2026-66608Medium· 6.4Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
CVE-2026-66580High· 8.5Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
CVE-2026-66579Medium· 6.5Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
CVE-2026-66578Medium· 6.5Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
CVE-2026-66577Medium· 6.5Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
CVE-2026-66576Medium· 6.5Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
CVE-2026-66575Medium· 5.3Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
CVE-2026-66574Medium· 6.5Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
CVE-2026-66573Medium· 6.5Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.
Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.
CVE-2026-66572Medium· 6.5Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.
Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.
CVE-2026-66571High· 7.1Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
CVE-2026-62108Critical· 9.8Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
CVE-2026-62104Critical· 10.0Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
CVE-2026-62101Critical· 9.8Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
CVE-2026-14850High· 8.8The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter
The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users…
CVE-2026-82723Low· 1.8Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…
Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…
CVE-2026-86522Medium· 6.3Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…
Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…