Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-57730

Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.

PUBLISHED
Vendor
UX-themes
Product
Flatsome
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5773

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network transfer operation that was requested by an application could wrongfully reuse an existing SMB connection to the same server that was using a different 'share' than the new subsequen

PUBLISHED
Vendor
curl
Product
curl
Provider severity
HIGH
Conflicts
0

CVE-2026-57729

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through <= 3.20.5.

PUBLISHED
Vendor
UX-themes
Product
Flatsome
Provider severity
HIGH
Conflicts
0

CVE-2026-57728

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through <= 3.20.5.

PUBLISHED
Vendor
UX-themes
Product
Flatsome
Provider severity
HIGH
Conflicts
0

CVE-2026-57727

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through <= 6.0.13.

PUBLISHED
Vendor
Themeum
Product
Kirki
Provider severity
HIGH
Conflicts
0

CVE-2026-57726

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through <= 6.0.12.

PUBLISHED
Vendor
Themeum
Product
Kirki
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57725

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through <= 6.0.11.

PUBLISHED
Vendor
Themeum
Product
Kirki
Provider severity
HIGH
Conflicts
0

CVE-2026-57724

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

PUBLISHED
Vendor
Themeum
Product
Kirki
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57723

Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.

PUBLISHED
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Provider severity
HIGH
Conflicts
0

CVE-2026-57722

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS. This issue affects Enable Media Replace: from n/a through 4.2.1.

PUBLISHED
Vendor
ShortPixel
Product
Enable Media Replace
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57721

Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.

PUBLISHED
Vendor
WP Reloaded
Product
ApplyOnline
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57720

Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.

PUBLISHED
Vendor
Codexpert Inc
Product
ThumbPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5772

A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname validation when the LEFT_MOST_WILDCARD_ONLY flag is active. If a wildcard * exhausts the entire hostname string, the function reads one byte past the buffer without a bounds check, which could cause a crash.

PUBLISHED
Vendor
wolfSSL
Product
wolfSSL
Provider severity
LOW
Conflicts
0

CVE-2026-57719

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.

PUBLISHED
Vendor
CodeRevolution
Product
Aimogen Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57718

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 2.0.12.

PUBLISHED
Vendor
Unlimited Elements
Product
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
Provider severity
HIGH
Conflicts
0

CVE-2026-57717

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

PUBLISHED
Vendor
knitpay
Product
Knit Pay
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57716

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

PUBLISHED
Vendor
videowhisper
Product
Broadcast Live Video
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57715

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fluent CRM: from n/a through <= 3.1.7.

PUBLISHED
Vendor
WPManageNinja
Product
Fluent CRM
Provider severity
HIGH
Conflicts
0

CVE-2026-57714

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3.

PUBLISHED
Vendor
LatePoint
Product
LatePoint
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57713

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

PUBLISHED
Vendor
Marcus (aka @msykes)
Product
Events Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-57712

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.

PUBLISHED
Vendor
WPZOOM
Product
WPZOOM Portfolio
Provider severity
HIGH
Conflicts
0

CVE-2026-57711

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.

PUBLISHED
Vendor
PSM Plugins
Product
SupportCandy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57710

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.

PUBLISHED
Vendor
quantumcloud
Product
WoowBot Pro Max
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57709

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.

PUBLISHED
Vendor
WP Swings
Product
Membership For WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-57708

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.

PUBLISHED
Vendor
CRM Perks
Product
Contact Form Entries
Provider severity
HIGH
Conflicts
0

CVE-2026-57707

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.

PUBLISHED
Vendor
quantumcloud
Product
Simple Business Directory Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57706

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.

PUBLISHED
Vendor
Dokan, Inc.
Product
Dokan
Provider severity
HIGH
Conflicts
0

CVE-2026-57705

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.

PUBLISHED
Vendor
Nexcess
Product
Event Tickets
Provider severity
HIGH
Conflicts
0

CVE-2026-57704

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

PUBLISHED
Vendor
StoreApps
Product
Smart Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-57703

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

PUBLISHED
Vendor
sunshinephotocart
Product
Sunshine Photo Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57702

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

PUBLISHED
Vendor
Melograno Venture Studio
Product
Amelia
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57701

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

PUBLISHED
Vendor
WebCodingPlace
Product
Real Estate Manager Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

PUBLISHED
Vendor
Daan.dev
Product
OMGF Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57699

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

PUBLISHED
Vendor
bqworks
Product
Slider Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-57698

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

PUBLISHED
Vendor
VillaTheme
Product
Abandoned Cart Recovery for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57697

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

PUBLISHED
Vendor
Metagauss
Product
ProfileGrid
Provider severity
HIGH
Conflicts
0

CVE-2026-57696

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

PUBLISHED
Vendor
videowhisper
Product
Picture Gallery
Provider severity
HIGH
Conflicts
0

CVE-2026-57695

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

PUBLISHED
Vendor
Dan Rossiter
Product
Document Gallery
Provider severity
HIGH
Conflicts
0

CVE-2026-57694

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

PUBLISHED
Vendor
Themeum
Product
Tutor LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57693

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ad Inserter: from n/a through <= 2.8.11.

PUBLISHED
Vendor
Spacetime
Product
Ad Inserter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.

PUBLISHED
Vendor
LCweb
Product
PrivateContent
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57691

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89.

PUBLISHED
Vendor
Eli
Product
Anti-Malware Security and Brute-Force Firewall
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57690

Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.

PUBLISHED
Vendor
Fuelthemes
Product
Werkstatt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57689

Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.

PUBLISHED
Vendor
Fuelthemes
Product
Werkstatt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57688

Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.

PUBLISHED
Vendor
Gurmehub
Product
POS Entegratör
Provider severity
HIGH
Conflicts
0

CVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

PUBLISHED
Vendor
Hiroaki Miyashita
Product
Custom Field Template
Provider severity
HIGH
Conflicts
0

CVE-2026-57686

Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.

PUBLISHED
Vendor
WPXPO
Product
WowAddons
Provider severity
HIGH
Conflicts
0

CVE-2026-57685

Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.

PUBLISHED
Vendor
drfuri
Product
Martfury - WooCommerce Marketplace WordPress Theme
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57684

Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.

PUBLISHED
Vendor
tranmautritam
Product
TheFox
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57683

Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.

PUBLISHED
Vendor
Epsiloncool
Product
WP Fast Total Search
Provider severity
CRITICAL
Conflicts
0