Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39634

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Grand Portfolio: from n/a through <= 3.3.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Portfolio
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39633

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request Forgery.This issue affects Grand Car Rental: from n/a through <= 3.6.9.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Car Rental
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39632

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: from n/a through <= 3.1.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Blog
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39631

Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPSchoolPress: from n/a through <= 2.2.35.

PUBLISHED
Vendor
Ronik@UnlimitedWP
Product
WPSchoolPress
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39630

Server-Side Request Forgery (SSRF) vulnerability in Getty Images Getty Images getty-images allows Server Side Request Forgery.This issue affects Getty Images: from n/a through <= 4.1.0.

PUBLISHED
Vendor
Getty Images
Product
Getty Images
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3963

A security flaw has been discovered in perfree go-fastdfs-web up to 1.3.7. This affects the function rememberMeManager of the file src/main/java/com/perfree/config/ShiroConfig.java of the component Apache Shiro RememberMe. Performing a manipulation results in use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. T

PUBLISHED
Vendor
perfree
Product
go-fastdfs-web
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-39629

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Uminex uminex allows Code Injection.This issue affects Uminex: from n/a through <= 1.0.9.

PUBLISHED
Vendor
kutethemes
Product
Uminex
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39628

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket dukamarket allows Code Injection.This issue affects DukaMarket: from n/a through <= 1.3.0.

PUBLISHED
Vendor
kutethemes
Product
DukaMarket
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39627

Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe: from n/a through <= 2.266.

PUBLISHED
Vendor
wproyal
Product
Ashe
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39626

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Armania armania allows Code Injection.This issue affects Armania: from n/a through <= 1.4.8.

PUBLISHED
Vendor
kutethemes
Product
Armania
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39625

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techone allows Code Injection.This issue affects TechOne: from n/a through <= 3.0.3.

PUBLISHED
Vendor
kutethemes
Product
TechOne
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39624

Missing Authorization vulnerability in kutethemes Biolife biolife allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Biolife: from n/a through <= 3.2.3.

PUBLISHED
Vendor
kutethemes
Product
Biolife
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39623

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Biolife biolife allows PHP Local File Inclusion.This issue affects Biolife: from n/a through <= 3.2.3.

PUBLISHED
Vendor
kutethemes
Product
Biolife
Provider severity
HIGH
Conflicts
0

CVE-2026-39622

Missing Authorization vulnerability in acmethemes Education Base education-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Base: from n/a through <= 3.0.8.

PUBLISHED
Vendor
acmethemes
Product
Education Base
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39621

Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.

PUBLISHED
Vendor
spicethemes
Product
SpicePress
Provider severity
HIGH
Conflicts
0

CVE-2026-39620

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.

PUBLISHED
Vendor
priyanshumittal
Product
Appointment
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3962

A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling rel

PUBLISHED
Vendor
Jcharis
Product
Machine-Learning-Web-Apps
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39619

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.

PUBLISHED
Vendor
priyanshumittal
Product
Busiprof
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39618

Cross-Site Request Forgery (CSRF) vulnerability in themearile NewsExo newsexo allows Cross Site Request Forgery.This issue affects NewsExo: from n/a through <= 7.1.

PUBLISHED
Vendor
themearile
Product
NewsExo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39617

Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.

PUBLISHED
Vendor
priyanshumittal
Product
Bluestreet
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39616

Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.4.0.

PUBLISHED
Vendor
dFactory
Product
Download Attachments
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39615

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Download Manager download-manager allows Stored XSS.This issue affects Download Manager: from n/a through <= 3.3.53.

PUBLISHED
Vendor
Shahjada
Product
Download Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39614

Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through <= 2.3.6.

PUBLISHED
Vendor
ilGhera
Product
JW Player for WordPress
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39613

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes Boutique kute-boutique allows PHP Local File Inclusion.This issue affects Boutique: from n/a through <= 2.3.3.

PUBLISHED
Vendor
kutethemes
Product
Boutique
Provider severity
HIGH
Conflicts
0

CVE-2026-39612

Missing Authorization vulnerability in kutethemes KuteShop kuteshop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KuteShop: from n/a through <= 4.2.9.

PUBLISHED
Vendor
kutethemes
Product
KuteShop
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39611

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in kutethemes KuteShop kuteshop allows PHP Local File Inclusion.This issue affects KuteShop: from n/a through <= 4.2.9.

PUBLISHED
Vendor
kutethemes
Product
KuteShop
Provider severity
HIGH
Conflicts
0

CVE-2026-39610

Missing Authorization vulnerability in Pankaj Kumar WpXmas-Snow wpxmas-snow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpXmas-Snow: from n/a through <= 1.1.

PUBLISHED
Vendor
Pankaj Kumar
Product
WpXmas-Snow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3961

A vulnerability was determined in zyddnys manga-image-translator up to beta-0.3. The affected element is the function to_pil_image of the file manga-image-translator-main/server/request_extraction.py of the component Translate Endpoints. This manipulation causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
zyddnys
Product
manga-image-translator
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39609

Missing Authorization vulnerability in Wava.co Wava Payment wava-payment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wava Payment: from n/a through <= 0.3.7.

PUBLISHED
Vendor
Wava.co
Product
Wava Payment
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39608

Missing Authorization vulnerability in iPOSPays iPOSpays Gateways WC ipospays-gateways-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iPOSpays Gateways WC: from n/a through <= 1.3.7.

PUBLISHED
Vendor
iPOSPays
Product
iPOSpays Gateways WC
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39607

Missing Authorization vulnerability in Wpbens Filter Plus filter-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter Plus: from n/a through <= 1.1.17.

PUBLISHED
Vendor
Wpbens
Product
Filter Plus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39606

Missing Authorization vulnerability in Foysal Imran BizReview bizreview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BizReview: from n/a through <= 1.5.13.

PUBLISHED
Vendor
Foysal Imran
Product
BizReview
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39605

Missing Authorization vulnerability in Obadiah Super Custom Login super-custom-login allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Custom Login: from n/a through <= 1.1.

PUBLISHED
Vendor
Obadiah
Product
Super Custom Login
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39604

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable allows Stored XSS.This issue affects MyBookTable Bookstore: from n/a through <= 3.6.0.

PUBLISHED
Vendor
zookatron
Product
MyBookTable Bookstore
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39603

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8.

PUBLISHED
Vendor
ThemeGoods
Product
Grand Photography
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39602

Missing Authorization vulnerability in Rustaurius Order Tracking order-tracking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Tracking: from n/a through <= 3.4.3.

PUBLISHED
Vendor
Rustaurius
Product
Order Tracking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3960

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to insufficient security controls in the parameter blacklist mechanism, which only targets MySQL JDBC driver-specific dangerous parameters. An attacker can bypass these controls by switching the JDBC URL protocol to jdbc:postgresql: and exploiting PostgreSQL JDBC driver-specific parameters such as socketFactory and soc

PUBLISHED
Vendor
h2oai
Product
h2oai/h2o-3
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39598

Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server. This issue affects Academy LMS Pro: from n/a before 3.5.2.

PUBLISHED
Vendor
Kodezen LLC
Product
Academy LMS Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-39597

Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.

PUBLISHED
Vendor
WPZOOM
Product
WPZOOM Addons for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-39596

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

PUBLISHED
Vendor
Creative Themes
Product
Blocksy Companion Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39595

Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.

PUBLISHED
Vendor
BoldGrid
Product
W3 Total Cache
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39594

Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.

PUBLISHED
Vendor
Themefic
Product
Ultra Addons for WPForms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39593

Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.10.

PUBLISHED
Vendor
VillaTheme
Product
HAPPY
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39592

Missing Authorization vulnerability in Andy Ha DEPART depart-deposit-and-part-payment-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DEPART: from n/a through <= 1.0.7.

PUBLISHED
Vendor
Andy Ha
Product
DEPART
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39591

Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

PUBLISHED
Vendor
CMSJunkie – WordPress Business Directory Plugins
Product
WP-BusinessDirectory
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39590

Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.

PUBLISHED
Vendor
ThemeMove
Product
Atomlab
Provider severity
HIGH
Conflicts
0

CVE-2026-3959

A vulnerability was found in 0xKoda WireMCP up to 7f45f8b2b4adeb76be8c6227eefb38533fdd6b1e. Impacted is the function server.tool of the file index.js of the component Tshark CLI Command Handler. The manipulation results in os command injection. The attack needs to be approached locally. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The

PUBLISHED
Vendor
0xKoda
Product
WireMCP
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39589

Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

PUBLISHED
Vendor
A WP Life
Product
Webenvo
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39588

Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13.

PUBLISHED
Vendor
nmerii
Product
NM Gift Registry and Wishlist Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39587

Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

PUBLISHED
Vendor
Hakan Ozevin
Product
WP BASE Booking
Provider severity
HIGH
Conflicts
0