Export limit exceeded: 404423 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404423 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-86798 | 2026-10-11 | 8.8 High | ||
| The HootBoard WordPress plugin through 3.1.4 does not perform any authorisation check on some of its REST endpoints, and does not escape the values stored through them before outputting them in a public page, allowing unauthenticated users to inject arbitrary web scripts that will execute in the browser of anyone visiting that page, including administrators. | ||||
| CVE-2026-108610 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AigcWordTemplateController edit handler that allows any authenticated user to modify word templates. Low-privileged attackers can send PUT or POST requests to /airag/word/edit to overwrite shared templates that other users rely on to generate documents. | ||||
| CVE-2026-108873 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify any department by calling PUT /sys/user/doUpdateDepartInfo. Attackers can supply a department id to rename or re-parent it and replace or remove its department heads without ownership or tenant checks. | ||||
| CVE-2026-107761 | 2026-10-11 | N/A | ||
| Several Postiz endpoints return the complete database row of the record they operate on instead of only the fields the client needs. Two of them include secrets the caller is not meant to receive. The public API's channel delete returns the deleted integration row, including the channel's platform access token and refresh token. A third-party OAuth app permitted to delete a channel therefore receives that channel's social platform credentials and can use them against the connected account directly, outside Postiz. `GET /user/organizations` returns each organization row, including its API key, to every member of the organization. The API key is intended for admins only, so a member with a lower role can obtain it and call the public API on behalf of the organization. Both endpoints require a valid session, API key or OAuth token and are scoped to the caller's own organization. There is no anonymous access and no cross-tenant exposure. | ||||
| CVE-2026-88905 | 2026-10-11 | 8.8 High | ||
| The KeyWord Collector WordPress plugin through 1.4 does not have any authorisation or nonce check when saving its settings, and does not escape them before output, allowing unauthenticated attackers to store malicious JavaScript that executes when an administrator opens the KeyWord Collector WordPress plugin through 1.4's settings page or when a visitor loads a page displaying its output. | ||||
| CVE-2026-89299 | 2026-10-11 | 8.6 High | ||
| The WP Verify API WordPress plugin through 1.0.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||||
| CVE-2026-89305 | 2026-10-11 | 6.5 Medium | ||
| The paymendo WordPress plugin through 1.1 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks. | ||||
| CVE-2026-103694 | 2026-10-11 | 8.8 High | ||
| The Mobile builder WordPress plugin through 1.4.2 does not properly restrict which user meta keys a logged-in user can update through one of its REST routes, allowing any user with a self-registered account, such as a customer, to grant themselves the administrator role. | ||||
| CVE-2026-104028 | 2026-10-11 | 9.8 Critical | ||
| The Anton Extensions WordPress plugin through 1.2.2 does not perform any capability check, nonce verification, or file-type validation before writing attacker-supplied content to an attacker-chosen path, allowing unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution. | ||||
| CVE-2026-104684 | 2026-10-11 | 2.7 Low | ||
| The Envira Gallery WordPress plugin before 1.16.2 does not verify that a user is authorized to read a gallery before rendering it, allowing authors to embed and expose other users' non-public gallery metadata to unauthenticated visitors. | ||||
| CVE-2026-107507 | 2026-10-11 | 2.7 Low | ||
| The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings and date of a sport they are assigned to. | ||||
| CVE-2026-86706 | 2026-10-11 | 9.1 Critical | ||
| The Quick quotes WordPress plugin through 1.0.0 does not perform any capability or nonce check on one of its AJAX actions and lets the caller choose which option is written, allowing unauthenticated users to alter arbitrary site settings and to make the site unavailable. | ||||
| CVE-2026-87764 | 2026-10-11 | 8.8 High | ||
| The BuddyPress Instant Chat WordPress plugin through 1.6 does not check that the sender of a chat message belongs to the conversation it is being added to, nor does it escape message content before outputting it back, allowing unauthenticated users to store arbitrary web scripts that will execute in the session of any member who later views that conversation. | ||||
| CVE-2026-88785 | 2026-10-11 | 4.7 Medium | ||
| The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them. | ||||
| CVE-2026-108905 | 2026-10-11 | 7.5 High | ||
| pH7Builder (pH7 Social Dating CMS) before 18.6.0 contains a hard-coded API key vulnerability in Tool.class.php that allows unauthenticated attackers to bypass API access checks by spoofing the Host header. Attackers can send Host: localhost with private_api_key=dev772277 and the default allowed URL to retrieve member emails, IP addresses, phone numbers, and bank account fields. | ||||
| CVE-2026-108904 | 2026-10-11 | 6.5 Medium | ||
| pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains an information disclosure vulnerability that allows API clients to obtain sensitive member data because UserController::users() and user() return unfiltered database rows. Attackers holding a valid private API key can retrieve bcrypt password hashes, non-expiring hashValidation reset tokens, and TOTP secrets to take over accounts and bypass two-factor authentication. | ||||
| CVE-2026-108903 | 2026-10-11 | 5.3 Medium | ||
| pH7Builder (pH7 Social Dating CMS) before 19.3.0 contains a CAPTCHA bypass vulnerability that allows unauthenticated attackers to skip form validation by supplying a client-chosen form ID to PFBC Form::isValid(). Attackers can load a CAPTCHA-free form like login or search, then submit its ID with contact, comment, forum, invite or signup data to automate abuse. | ||||
| CVE-2026-108902 | 2026-10-11 | 8.1 High | ||
| pH7Builder (pH7 Social Dating CMS) before 18.5.0 contains a path traversal vulnerability in the picture module deletePhoto() action that allows authenticated members to delete arbitrary files. Attackers can supply ../ sequences in the POST picture_link parameter to remove other members' photos or configuration and cache files, causing content loss and denial of service. | ||||
| CVE-2026-108684 | 1 Jeewms | 1 Jeewms | 2026-10-11 | 6.3 Medium |
| A vulnerability was detected in erzhongxmu Jeewms up to 3.7. This affects the function getTreeData of the file src/main/java/com/jeecg/demo/controller/JeecgFormDemoController.java of the component Autocomplete Data Handler. Performing a manipulation of the argument searchVal results in sql injection. The attack can be initiated remotely. The patch is named 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0. It is recommended to apply a patch to fix this issue. | ||||
| CVE-2026-88903 | 2026-10-11 | 8.8 High | ||
| The Topcontent WordPress plugin through 1.2.1 does not properly authorise one of its request handlers and disables HTML sanitisation before storing the submitted content, allowing unauthenticated attackers to publish arbitrary posts containing malicious JavaScript on any site where its API key has never been configured. | ||||
