VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25160 CVEsRSS

CVE-2026-92106Low· 2.3
3d ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. LazyHTML.to_html/2 and LazyHTM…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. LazyHTML.to_html/2 and LazyHTM…

▾ Sunlitdashbitco · lazy_htmlEPSS 0.39%via NVD
CVE-2026-97863Medium· 6.3
3d ago

The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API

The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to and calls the Cisco fireSIGHT Manager API. The module interpolates configuration values (IP address, login, password,…

▾ Sunlitmisp · misp-modulesEPSS 0.32%via NVD
CVE-2026-92550High· 7.5
3d ago

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…

▾ TwilightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocolEPSS 0.37%via NVD
CVE-2026-92573Medium· 6.5
3d ago

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memo…

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memo…

▾ SunlitApache Software Foundation · org.apache.qpid:qpid-broker-coreEPSS 0.29%via NVD
CVE-2026-92564High· 7.5
3d ago

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1…

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1…

▾ TwilightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocolEPSS 0.19%via NVD
CVE-2026-92560High· 7.5
3d ago

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to ve…

▾ TwilightApache Software Foundation · org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocolEPSS 0.37%via NVD
CVE-2026-6082Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/payment-methods' that allow the injection and persistence …

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-86837Medium· 5.3
3d ago

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored …

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored …

▾ SunlitEPSS 0.18%via NVD
CVE-2026-6085Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types' that allow the injection and persiste…

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-6083Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint ' /inventory/configuration/pricing-tiers' that allow the injection and persistence o…

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-6087Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow the injection and persistence of ma…

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-6086Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/serial-number-types' that allow the injection and persiste…

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-6084Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/variants' that allow the injection and persistence of mali…

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-88848Medium· 4.2
3d ago

The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, a…

The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their membership plan, nor that the plan identifier submitted with the request is one they actually hold, a…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-6088Medium· 5.1
3d ago

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel

Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on the server side in REST endpoint '/inventory/configuration/categories' that allow the injection and persistence of ma…

▾ SunlitNovadigits technologies · StockAgileEPSS 0.23%via NVD
CVE-2026-80514Medium· 5.3
3d ago

The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to byp…

The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its per-visitor rate limit on paid AI requests, allowing unauthenticated attackers to byp…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-19804High· 8.8
3d ago

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_nam…

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_nam…

▾ Twilightclavaque · s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access SubscriptionsEPSS 1.0%via NVD
CVE-2026-12037Medium· 5.5
3d ago

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the 'page_url' parameter. This makes it possible for authenticated attackers, with …

▾ Sunlitgabelivan · Asset CleanUp: Page Speed BoosterEPSS 0.29%via NVD
CVE-2026-96448Medium· 6.6
3d ago

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the system checks if a delegated administrator has permission to assign a specific ro…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-88996Medium· 6.1
3d ago

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all v…

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all v…

▾ Sunlitsmub · WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & MoreEPSS 0.27%via NVD
CVE-2026-93747Medium· 6.4
3d ago

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This is due to insufficient input sanitization and output escaping in the profil…

▾ Sunlittomdever · wpForo ForumEPSS 0.20%via NVD
CVE-2026-96752High· 7.2
3d ago

The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in all versions up to, and including, 5.7.10 due to insufficient input sanitization a…

The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration in all versions up to, and including, 5.7.10 due to insufficient input sanitization a…

▾ Twilightbmarshall511 · Zero Spam for WordPressEPSS 0.24%via NVD
CVE-2026-13456High· 7.5
3d ago

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This make…

▾ Twilightflippercode · WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & ListingsEPSS 0.75%via NVD
CVE-2026-84280High· 7.2
3d ago

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output e…

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output e…

▾ Twilightradykal · Fancy Product DesignerEPSS 0.27%via NVD
CVE-2026-17577Medium· 6.1
3d ago

The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42

The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42. The ssl_zen_messages::getMessages() function builds the 'token_missmatch' me…

▾ Sunlitsslzen · SSL Zen — SSL Certificate Installer & HTTPS RedirectsEPSS 0.27%via NVD
CVE-2026-93654High· 7.2
3d ago

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, and including, 7.2.1 due to insufficient input sani…

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, and including, 7.2.1 due to insufficient input sani…

▾ Twilightcodename065 · Premium Packages – Sell Digital Products SecurelyEPSS 0.24%via NVD
CVE-2026-92713High· 8.1
3d ago

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2

The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the upload_image function in all versions up to, and including, 3.0.2. This m…

▾ Twilightwpchill · Modula Image Gallery – Photo Grid & Video GalleryEPSS 0.27%via NVD
CVE-2026-96568High· 7.2
3d ago

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escap…

The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escap…

▾ Twilightjetmonsters · Restaurant Menu and Food OrderingEPSS 0.24%via NVD
CVE-2026-93656Medium· 6.4
3d ago

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insuffic…

▾ Sunlitcozmoslabs · User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorEPSS 0.20%via NVD
CVE-2026-94573High· 7.2
3d ago

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. Th…

▾ Twilightaddonsorg · Repeater Fields for Elementor FormsEPSS 0.24%via NVD
CVEs tagged “nvd” — page 35 · VulnSea