Export limit exceeded: 369812 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (369812 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65478 2026-07-23 5.4 Medium
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
CVE-2026-65477 2026-07-23 7.5 High
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
CVE-2026-57785 2026-07-23 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
CVE-2026-65476 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
CVE-2026-57769 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
CVE-2026-27064 2026-07-23 9.1 Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-27377 2026-07-23 6.7 Medium
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
CVE-2026-15017 2 Mdjm, Wordpress 2 Mdjm Event Management, Wordpress 2026-07-23 8.8 High
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.
CVE-2026-15448 2 Tickera, Wordpress 2 Tickera – Sell Tickets & Manage Events, Wordpress 2026-07-23 6.5 Medium
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-65550 2026-07-23 5.9 Medium
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65540 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65539 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65536 2026-07-23 6.5 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65535 2026-07-23 4.3 Medium
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65534 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65533 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65532 2026-07-23 7.6 High
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65531 2026-07-23 4.8 Medium
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.