Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-40832

An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, MB connect line, MB connect line, MB connect line, MB connect line, Helmholz, Helmholz, Helmholz
Product
myREX24V2.virtual, mbCONNECT24, mbCONNECT24, mymbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2, myREX24V2.virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40831

An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
MB connect line, MB connect line, Helmholz, Helmholz, MB connect line, Helmholz, MB connect line, Helmholz
Product
mymbCONNECT24, mbCONNECT24, myREX24V2, myREX24V2.virtual, mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, myREX24V2
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40830

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php files UpdateParam function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
Helmholz, MB connect line, Helmholz, MB connect line, MB connect line, Helmholz, MB connect line, Helmholz
Product
myREX24V2, mymbCONNECT24, myREX24V2, mbCONNECT24, mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, myREX24V2.virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-4083

The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small blacklist of four attribute names (same_height_as, onload, onpageshow, onclick) being blocked. While the attribute names are passed through esc_html() and values through esc_attr(), this

PUBLISHED
Vendor
demonisblack
Product
Scoreboard for HTML5 Games Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40829

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the view.html.php files UpdateParam function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
MB connect line, Helmholz, MB connect line, MB connect line, Helmholz, Helmholz, MB connect line, Helmholz
Product
mymbCONNECT24, myREX24V2, mbCONNECT24, mbCONNECT24, myREX24V2, myREX24V2.virtual, mymbCONNECT24, myREX24V2.virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40828

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry function due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
Helmholz, MB connect line, Helmholz, Helmholz, MB connect line, MB connect line, MB connect line, Helmholz
Product
myREX24V2, mbCONNECT24, myREX24V2, myREX24V2.virtual, mymbCONNECT24, mymbCONNECT24, mbCONNECT24, myREX24V2.virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40827

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest function due to improper neutralization of special elements in a SQL DELETE command allowing for reading the whole database and deleting entries in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
Helmholz, Helmholz, MB connect line, Helmholz, MB connect line, MB connect line, MB connect line, Helmholz
Product
myREX24V2, myREX24V2, mymbCONNECT24, myREX24V2.virtual, mbCONNECT24, mbCONNECT24, mymbCONNECT24, myREX24V2.virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40826

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, MB connect line, MB connect line, MB connect line, MB connect line, Helmholz, Helmholz, Helmholz
Product
myREX24V2.virtual, mbCONNECT24, mymbCONNECT24, mymbCONNECT24, mbCONNECT24, myREX24V2.virtual, myREX24V2, myREX24V2
Provider severity
MEDIUM
Conflicts
2

CVE-2026-40825

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view devices parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
MB connect line, MB connect line, MB connect line, Helmholz, MB connect line, Helmholz, Helmholz, Helmholz
Product
mymbCONNECT24, mbCONNECT24, mymbCONNECT24, myREX24V2, mbCONNECT24, myREX24V2.virtual, myREX24V2, myREX24V2.virtual
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40824

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view userid parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
Helmholz, MB connect line, Helmholz, Helmholz, MB connect line, Helmholz, MB connect line, MB connect line
Product
myREX24V2.virtual, mymbCONNECT24, myREX24V2, myREX24V2, mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, mbCONNECT24
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40823

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result in a total loss of confidentiality and some loss of integrity.

PUBLISHED
Vendor
Helmholz, MB connect line, MB connect line, MB connect line, Helmholz, Helmholz, Helmholz, MB connect line
Product
myREX24V2, mbCONNECT24, mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual, myREX24V2.virtual, mymbCONNECT24
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-40822

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, Helmholz, Helmholz, MB connect line, MB connect line, MB connect line, Helmholz, MB connect line
Product
myREX24V2.virtual, myREX24V2, myREX24V2, mymbCONNECT24, mymbCONNECT24, mbCONNECT24, myREX24V2.virtual, mbCONNECT24
Provider severity
MEDIUM
Conflicts
2

CVE-2026-40821

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, Helmholz, MB connect line, Helmholz, MB connect line, Helmholz, MB connect line, MB connect line
Product
myREX24V2, myREX24V2, mbCONNECT24, myREX24V2.virtual, mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, mymbCONNECT24
Provider severity
MEDIUM
Conflicts
2

CVE-2026-4082

The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including 1.0.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes ('n', 'w', 'h'). These attributes are extracted using extract() and directly interpolated into the HTML output without any escaping such as esc_attr(). This makes it possible for authenticated attackers, with Contributor-level access and

PUBLISHED
Vendor
erithq
Product
ER Swiffy Insert
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40819

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, Helmholz, Helmholz, MB connect line, MB connect line, MB connect line, Helmholz, MB connect line
Product
myREX24V2.virtual, myREX24V2.virtual, myREX24V2, mbCONNECT24, mymbCONNECT24, mbCONNECT24, myREX24V2, mymbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40818

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
MB connect line, MB connect line, Helmholz, MB connect line, Helmholz, MB connect line, Helmholz, Helmholz
Product
mymbCONNECT24, mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, myREX24V2, mbCONNECT24, myREX24V2.virtual, myREX24V2
Provider severity
HIGH
Conflicts
2

CVE-2026-40817

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, Helmholz, MB connect line, Helmholz, Helmholz, MB connect line, MB connect line, MB connect line
Product
myREX24V2.virtual, myREX24V2, mbCONNECT24, myREX24V2.virtual, myREX24V2, mymbCONNECT24, mbCONNECT24, mymbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40816

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, Helmholz, MB connect line, MB connect line, MB connect line, Helmholz, Helmholz, MB connect line
Product
myREX24V2, myREX24V2, mbCONNECT24, mymbCONNECT24, mymbCONNECT24, myREX24V2.virtual, myREX24V2.virtual, mbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40815

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, MB connect line, Helmholz, Helmholz, MB connect line, Helmholz, MB connect line, MB connect line
Product
myREX24V2, mymbCONNECT24, myREX24V2, myREX24V2.virtual, mymbCONNECT24, myREX24V2.virtual, mbCONNECT24, mbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40814

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
MB connect line, Helmholz, Helmholz, Helmholz, MB connect line, MB connect line, Helmholz, MB connect line
Product
mbCONNECT24, myREX24V2.virtual, myREX24V2.virtual, myREX24V2, mbCONNECT24, mymbCONNECT24, myREX24V2, mymbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40813

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, MB connect line, MB connect line, Helmholz, Helmholz, MB connect line, Helmholz, MB connect line
Product
myREX24V2.virtual, mbCONNECT24, mymbCONNECT24, myREX24V2.virtual, myREX24V2, mbCONNECT24, myREX24V2, mymbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40812

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions sn parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
MB connect line, Helmholz, MB connect line, Helmholz, MB connect line, MB connect line, Helmholz, Helmholz
Product
mymbCONNECT24, myREX24V2.virtual, mbCONNECT24, myREX24V2.virtual, mymbCONNECT24, mbCONNECT24, myREX24V2, myREX24V2
Provider severity
HIGH
Conflicts
2

CVE-2026-40811

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
MB connect line, Helmholz, MB connect line, Helmholz, Helmholz, Helmholz, MB connect line, MB connect line
Product
mbCONNECT24, myREX24V2, mymbCONNECT24, myREX24V2.virtual, myREX24V2, myREX24V2.virtual, mbCONNECT24, mymbCONNECT24
Provider severity
HIGH
Conflicts
2

CVE-2026-40810

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

PUBLISHED
Vendor
Helmholz, Helmholz, MB connect line, MB connect line, MB connect line, Helmholz, MB connect line, Helmholz
Product
myREX24V2, myREX24V2.virtual, mbCONNECT24, mbCONNECT24, mymbCONNECT24, myREX24V2, mymbCONNECT24, myREX24V2.virtual
Provider severity
HIGH
Conflicts
2

CVE-2026-4081

The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'url', 'color', and 'bgcolor' parameters. These attribute values are directly interpolated into HTML attribute context without being passed through esc_attr() or any other escaping function. This makes it possible for authenticated

PUBLISHED
Vendor
jhdscript
Product
ZeM STL
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40809

Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.4.1.

PUBLISHED
Vendor
Rara Themes
Product
Metro Magazine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4080

The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all versions up to and including 1.8. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. Specifically, the ectp_add_to_cart() function uses sanitize_text_field() on shortcode attributes like 'itemid', 'product_name', 'product_desc', 'product_qty', and 'price' before inserting them into double-quoted HTML attributes. While saniti

PUBLISHED
Vendor
zeshanb
Product
Easy Cart
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40799

Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.

PUBLISHED
Vendor
RelyWP
Product
Simple Cloudflare Turnstile
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40798

Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.

PUBLISHED
Vendor
Tomdever
Product
wpForo Forum
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40797

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: from n/a through 4.08.253.

PUBLISHED
Vendor
Saleswonder LLC
Product
WebinarIgnition
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40796

Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.

PUBLISHED
Vendor
ollybach
Product
WPPizza
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40795

Subscriber Broken Access Control in Amelia <= 2.2 versions.

PUBLISHED
Vendor
TMS
Product
Amelia
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40794

Subscriber Broken Access Control in myCred <= 3.0.3 versions.

PUBLISHED
Vendor
myCred
Product
myCred
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40793

Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

PUBLISHED
Vendor
Groundhogg
Product
Groundhogg
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40792

Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.

PUBLISHED
Vendor
Iqonic Design
Product
KiviCare
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40791

Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.

PUBLISHED
Vendor
codepeople
Product
WP Time Slots Booking Form
Provider severity
HIGH
Conflicts
0

CVE-2026-40790

Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.

PUBLISHED
Vendor
VeronaLabs
Product
WP SMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4079

The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queries, making it possible for attackers to conduct SQL Injection attacks against the dynamic filter functionality.

PUBLISHED
Vendor
Unknown
Product
SQL Chart Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40789

Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.

PUBLISHED
Vendor
TMS
Product
Amelia
Provider severity
HIGH
Conflicts
0

CVE-2026-40788

Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.

PUBLISHED
Vendor
QuantumCloud
Product
ChatBot
Provider severity
HIGH
Conflicts
0

CVE-2026-40787

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.

PUBLISHED
Vendor
ExpressTech
Product
Quiz And Survey Master
Provider severity
HIGH
Conflicts
0

CVE-2026-40786

Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.

PUBLISHED
Vendor
Long Watch Studio
Product
MyRewards
Provider severity
MEDIUM
Conflicts
1

CVE-2026-40785

Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.

PUBLISHED
Vendor
Ruben Garcia
Product
AutomatorWP
Provider severity
HIGH
Conflicts
0

CVE-2026-40784

Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.2.

PUBLISHED
Vendor
Mahmudul Hasan Arif
Product
FluentBoards
Provider severity
HIGH
Conflicts
1

CVE-2026-40783

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

PUBLISHED
Vendor
Creative Themes
Product
Blocksy Companion Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-40782

Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.

PUBLISHED
Vendor
Greg Winiarski
Product
WPAdverts
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40781

Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.

PUBLISHED
Vendor
ReviewX
Product
ReviewX
Provider severity
HIGH
Conflicts
0

CVE-2026-40780

Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1.

PUBLISHED
Vendor
Liquid Web / StellarWP
Product
BookIt
Provider severity
HIGH
Conflicts
0

CVE-2026-4078

The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, iteras-signup, iteras-paywall-login, iteras-selfservice) in all versions up to and including 1.8.2. This is due to insufficient input sanitization and output escaping in the combine_attributes() function. The function directly concatenates shortcode attribute values into JavaScript code within <script> tags using double-quoted string interpolation (line 489: '"'.$key.'": "'.$val

PUBLISHED
Vendor
iteras
Product
ITERAS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-40779

Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.

PUBLISHED
Vendor
Yannick Lefebvre
Product
Link Library
Provider severity
HIGH
Conflicts
0