Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-56062

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

PUBLISHED
Vendor
oooorgle
Product
Quotes llama
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56061

Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.

PUBLISHED
Vendor
WP Swings
Product
Subscriptions for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-56060

Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

PUBLISHED
Vendor
tychesoftwares
Product
Print Invoice & Delivery Notes for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-5606

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-details.php of the component Parameter Handler. The manipulation of the argument orderid results in sql injection. It is possible to launch the attack remotely.

PUBLISHED
Vendor
PHPGurukul
Product
Online Shopping Portal Project
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

PUBLISHED
Vendor
PhysCode
Product
Travel Booking
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56058

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

PUBLISHED
Vendor
ThemeCatcher
Product
Quform
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56057

Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

PUBLISHED
Vendor
Uncanny Owl
Product
Uncanny Automator Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56055

Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.

PUBLISHED
Vendor
InspiryThemes
Product
RealHomes
Provider severity
HIGH
Conflicts
0

CVE-2026-56054

Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.

PUBLISHED
Vendor
Ahmad
Product
JS Help Desk
Provider severity
HIGH
Conflicts
0

CVE-2026-56053

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

PUBLISHED
Vendor
EventPrime
Product
EventPrime
Provider severity
HIGH
Conflicts
0

CVE-2026-56052

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5.

PUBLISHED
Vendor
FunnelKit
Product
Funnel Builder by FunnelKit
Provider severity
HIGH
Conflicts
0

CVE-2026-56051

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

PUBLISHED
Vendor
TablePress
Product
TablePress
Provider severity
HIGH
Conflicts
0

CVE-2026-56050

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.

PUBLISHED
Vendor
Themeisle
Product
PPOM for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5605

A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

PUBLISHED
Vendor
Tenda
Product
CH22
Provider severity
HIGH
Conflicts
2

CVE-2026-56049

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

PUBLISHED
Vendor
Post Snippets
Product
Post Snippets
Provider severity
HIGH
Conflicts
0

CVE-2026-56048

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.

PUBLISHED
Vendor
tychesoftwares
Product
Payment Gateway Based Fees and Discounts for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56047

Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.

PUBLISHED
Vendor
Perfmatters, Powered Kinsta + GeneratePress Docs Changelog Feature requests Legal Affiliate Contact
Product
perfmatters
Provider severity
HIGH
Conflicts
0

CVE-2026-56046

Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56045

Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.

PUBLISHED
Vendor
ValvePress
Product
Automatic
Provider severity
HIGH
Conflicts
0

CVE-2026-56044

Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.

PUBLISHED
Vendor
Adenion
Product
Blog2Social
Provider severity
HIGH
Conflicts
0

CVE-2026-56043

Unauthenticated Cross Site Scripting (XSS) in Customer Reviews for WooCommerce <= 5.110.1 versions.

PUBLISHED
Vendor
CusRev
Product
Customer Reviews for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-56042

Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

PUBLISHED
Vendor
Algolplus
Product
Advanced Order Export For WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-56041

Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.

PUBLISHED
Vendor
dFactory
Product
Responsive Lightbox
Provider severity
HIGH
Conflicts
0

CVE-2026-56040

Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.

PUBLISHED
Vendor
WordPress.com
Product
Gutenverse Form
Provider severity
HIGH
Conflicts
0

CVE-2026-5604

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

PUBLISHED
Vendor
Tenda
Product
CH22
Provider severity
HIGH
Conflicts
2

CVE-2026-56039

Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.

PUBLISHED
Vendor
WordPress.com
Product
Quick Interest Slider
Provider severity
HIGH
Conflicts
0

CVE-2026-56038

Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.

PUBLISHED
Vendor
Frisbii
Product
Frisbii Pay
Provider severity
HIGH
Conflicts
0

CVE-2026-56037

Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.

PUBLISHED
Vendor
Themify
Product
Themify Popup
Provider severity
HIGH
Conflicts
0

CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

PUBLISHED
Vendor
codemstory
Product
워드프레스 결제 심플페이
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56035

Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.

PUBLISHED
Vendor
Cory Marsh
Product
BitFire Security
Provider severity
HIGH
Conflicts
0

CVE-2026-56034

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

PUBLISHED
Vendor
Online Web Tutor
Product
Library Management System
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56033

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

PUBLISHED
Vendor
Dokan Multivendor Plugin
Product
Dokan Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56032

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

PUBLISHED
Vendor
BuddyBoss
Product
Buddyboss Platform
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56031

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

PUBLISHED
Vendor
Uncanny Owl
Product
Uncanny Automator
Provider severity
HIGH
Conflicts
0

CVE-2026-56030

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

PUBLISHED
Vendor
paytiumsupport
Product
Paytium
Provider severity
CRITICAL
Conflicts
0

CVE-2026-5603

A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.

PUBLISHED
Vendor
elgentos
Product
magento2-dev-mcp
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56029

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

PUBLISHED
Vendor
corvuspay
Product
CorvusPay WooCommerce Payment Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-56028

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

PUBLISHED
Vendor
themewant
Product
Easy Elements for Elementor &#8211; Addons &amp; Website Templates
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56027

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

PUBLISHED
Vendor
Pluggabl
Product
Booster for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-56026

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

PUBLISHED
Vendor
Chris Carlevato
Product
utm.codes
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56025

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

PUBLISHED
Vendor
Paymob
Product
Paymob for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-56024

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.

PUBLISHED
Vendor
Saad Iqbal
Product
WP EasyPay
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56023

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

PUBLISHED
Vendor
Knit Pay
Product
UPI QR Code Payment Gateway for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-56022

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

PUBLISHED
Vendor
Webmin
Product
Webmin
Provider severity
MEDIUM
Conflicts
1

CVE-2026-56021

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

PUBLISHED
Vendor
Webmin
Product
Webmin
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56020

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.

PUBLISHED
Vendor
Webmin
Product
Webmin
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-5602

A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contact

PUBLISHED
Vendor
Nor2-io
Product
heim-mcp
Provider severity
MEDIUM
Conflicts
2

CVE-2026-56018

JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) the cleanup frees only the NodeSet structures and never the per-token contents buffers allocated in JsSetNodeContents; JsDiscardNode unlinks nodes without freeing their contents. Each token's contents buffer is therefore leaked on every call, and the two early returns taken when the node list is empty leak the whole NodeSet. A long-lived process th

PUBLISHED
Vendor
GTERMARS
Product
JavaScript::Minifier::XS
Provider severity
HIGH
Conflicts
1

CVE-2026-56017

JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. The regexp versus division disambiguator in JsTokenizeString (XS.xs) inspects the previous token's last byte to choose between a regexp literal and a division operator. When a slash is the first meaningful token, with the start of input or only whitespace and comments before it, there is no valid preceding token: the walk back over whitespace and

PUBLISHED
Vendor
GTERMARS
Product
JavaScript::Minifier::XS
Provider severity
HIGH
Conflicts
1

CVE-2026-56016

CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of the process id, the epoch time, and the built-in rand() function. All three are predictable, low-entropy sources: the PID is drawn from a small range, the epoch time can be guessed or read from the HTTP Date header, and Perl's rand() is unsuitable for security purposes because it is predictable and reversible. An attack

PUBLISHED
Vendor
MARKSTOS
Product
CGI::Session::ID::md5
Provider severity
MEDIUM
Conflicts
1