Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-42738

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0.

PUBLISHED
Vendor
ZAYTECH
Product
Smart Online Order for Clover
Provider severity
HIGH
Conflicts
0

CVE-2026-42737

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

PUBLISHED
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Provider severity
HIGH
Conflicts
0

CVE-2026-42736

Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Better Messages: from n/a through <= 2.14.16.

PUBLISHED
Vendor
wordplus
Product
BP Better Messages
Provider severity
HIGH
Conflicts
0

CVE-2026-42735

Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.

PUBLISHED
Vendor
Iqonic Design
Product
KiviCare
Provider severity
HIGH
Conflicts
0

CVE-2026-42734

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup geo-mashup allows Reflected XSS.This issue affects Geo Mashup: from n/a through <= 1.13.19.

PUBLISHED
Vendor
Dylan Kuhn
Product
Geo Mashup
Provider severity
HIGH
Conflicts
0

CVE-2026-42733

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS currency-switcher allows DOM-Based XSS.This issue affects WPCS: from n/a through <= 1.3.1.

PUBLISHED
Vendor
RealMag777
Product
WPCS
Provider severity
HIGH
Conflicts
0

CVE-2026-42732

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Input Data Manipulation.This issue affects Ads by WPQuads: from n/a through <= 3.0.2.

PUBLISHED
Vendor
Ads by WPQuads
Product
Ads by WPQuads
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42731

Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.

PUBLISHED
Vendor
miniOrange
Product
miniorange otp verification
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42730

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection.This issue affects MasterStudy LMS: from n/a through <= 3.7.29.

PUBLISHED
Vendor
Stylemix
Product
MasterStudy LMS
Provider severity
HIGH
Conflicts
0

CVE-2026-4273

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a crafted invite confirmation with a RefreshedToken matching the original token. Mattermost Advisory ID: MMSA-2026-00575

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
LOW
Conflicts
0

CVE-2026-42729

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2.

PUBLISHED
Vendor
Property Hive
Product
PropertyHive
Provider severity
HIGH
Conflicts
0

CVE-2026-42728

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2.

PUBLISHED
Vendor
HT Plugins
Product
HT Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-42727

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8.

PUBLISHED
Vendor
RealMag777
Product
Active Products Tables for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42726

Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= 4.4.5.

PUBLISHED
Vendor
Strategy11 Team
Product
AWP Classifieds
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42725

Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.5.

PUBLISHED
Vendor
WP Wham
Product
Checkout Files Upload for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4272

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK000765BAA_CU000101BAA. This vulnerability could allow a remote attacker within Bluetooth range of the scanner's base station has the capability to remotely execute system commands on the host connected t

PUBLISHED
Vendor
Honeywell
Product
Barcode Scanners
Provider severity
HIGH
Conflicts
0

CVE-2026-4271

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server implementation. A remote attacker can exploit this by sending specially crafted HTTP/2 requests that cause authentication failures. This can lead to the application attempting to access memory that has already been freed, potentially causing application instability or crashes, resulting in a Denial of Service (DoS).

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10.0 Extended Update Support
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4270

Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.

PUBLISHED
Vendor
AWS
Product
AWS API MCP Server
Provider severity
MEDIUM
Conflicts
1

CVE-2026-4269

A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build or have built the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not a

PUBLISHED
Vendor
AWS
Product
Bedrock AgentCore Starter Toolkit
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-42688

Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.

PUBLISHED
Vendor
WP Chill
Product
Modula Image Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42687

Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.

PUBLISHED
Vendor
EventPrime
Product
EventPrime
Provider severity
HIGH
Conflicts
0

CVE-2026-42686

Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.

PUBLISHED
Vendor
EventPrime
Product
EventPrime
Provider severity
HIGH
Conflicts
0

CVE-2026-42685

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.

PUBLISHED
Vendor
Ahmad
Product
WP Job Portal
Provider severity
HIGH
Conflicts
0

CVE-2026-42684

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Portal allows Blind SQL Injection. This issue affects WP Job Portal: from n/a through 2.5.1.

PUBLISHED
Vendor
Ahmad
Product
WP Job Portal
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42683

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

PUBLISHED
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Provider severity
HIGH
Conflicts
0

CVE-2026-42682

Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

PUBLISHED
Vendor
Tomdever
Product
wpForo Forum
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42681

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

PUBLISHED
Vendor
E2Pdf.com
Product
e2pdf
Provider severity
HIGH
Conflicts
0

CVE-2026-42680

Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

PUBLISHED
Vendor
Wasiliy Strecker / ContestGallery developer
Product
Contest Gallery Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4268

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' hook anonymous function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whene

PUBLISHED
Vendor
wpgmaps
Product
WP Go Maps (formerly WP Google Maps)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42679

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

PUBLISHED
Vendor
Mamunur Rashid
Product
Classified Listing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42678

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.

PUBLISHED
Vendor
Liquid Web / StellarWP
Product
GiveWP
Provider severity
HIGH
Conflicts
0

CVE-2026-42677

Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

PUBLISHED
Vendor
Ben Balter
Product
WP Document Revisions
Provider severity
HIGH
Conflicts
0

CVE-2026-42676

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

PUBLISHED
Vendor
myCred
Product
myCred
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42675

Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

PUBLISHED
Vendor
Themefic
Product
Hydra Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-42674

Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

PUBLISHED
Vendor
AAM Plugin
Product
Advanced Access Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-42673

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6.

PUBLISHED
Vendor
Logtivity Activity Logs
Product
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
Provider severity
HIGH
Conflicts
0

CVE-2026-42672

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

PUBLISHED
Vendor
Wp Directory Kit
Product
WP Directory Kit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42671

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

PUBLISHED
Vendor
Paolo
Product
GeoDirectory
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42670

Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14.

PUBLISHED
Vendor
Etoile Web Design Incorporated
Product
Five Star Restaurant Reservations
Provider severity
HIGH
Conflicts
0

CVE-2026-4267

The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PUBLISHED
Vendor
johnbillion
Product
Query Monitor
Provider severity
HIGH
Conflicts
0

CVE-2026-42669

Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects EventPrime: from n/a through 4.3.2.0.

PUBLISHED
Vendor
EventPrime
Product
EventPrime
Provider severity
HIGH
Conflicts
0

CVE-2026-42668

Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.

PUBLISHED
Vendor
Omnisend
Product
Email Marketing for WooCommerce by Omnisend
Provider severity
HIGH
Conflicts
0

CVE-2026-42667

Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.

PUBLISHED
Vendor
Bookly
Product
Bookly
Provider severity
HIGH
Conflicts
0

CVE-2026-42666

Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.

PUBLISHED
Vendor
Dimitri Grassi
Product
Salon booking system
Provider severity
HIGH
Conflicts
0

CVE-2026-42665

Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

PUBLISHED
Vendor
Passionate Programmer Peter
Product
WP Data Access
Provider severity
CRITICAL
Conflicts
0

CVE-2026-42664

Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1.38.2 versions.

PUBLISHED
Vendor
Motive Commerce Search
Product
AI Product Search for WooCommerce &#8211; Motive Commerce Search
Provider severity
HIGH
Conflicts
0

CVE-2026-42663

Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.

PUBLISHED
Vendor
wp.insider
Product
Simple Membership
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42662

Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.

PUBLISHED
Vendor
Liquid Web / StellarWP
Product
Event Tickets
Provider severity
MEDIUM
Conflicts
0

CVE-2026-42661

Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.

PUBLISHED
Vendor
aguilatechnologies
Product
WP Customer Area
Provider severity
HIGH
Conflicts
0

CVE-2026-42660

Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.

PUBLISHED
Vendor
Wasiliy Strecker
Product
Contest Gallery
Provider severity
MEDIUM
Conflicts
0