Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39540

Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

PUBLISHED
Vendor
Amit Mittal
Product
Shipment Tracker for Woocommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3954

A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application/routers/workspace.py. This manipulation of the argument file_name causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
OpenBMB
Product
XAgent
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39539

Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.

PUBLISHED
Vendor
Edge-Themes
Product
Alloggio - Hotel Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-39538

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Mikado Core mikado-core allows PHP Local File Inclusion.This issue affects Mikado Core: from n/a through <= 1.6.

PUBLISHED
Vendor
Mikado-Themes
Product
Mikado Core
Provider severity
HIGH
Conflicts
0

CVE-2026-39537

Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.

PUBLISHED
Vendor
Mikado-Themes
Product
Mikado Core
Provider severity
HIGH
Conflicts
0

CVE-2026-39536

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WP Chill RSVP and Event Management rsvp allows Retrieve Embedded Sensitive Data.This issue affects RSVP and Event Management: from n/a through <= 2.7.16.

PUBLISHED
Vendor
WP Chill
Product
RSVP and Event Management
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39535

Missing Authorization vulnerability in fullworks Display Eventbrite Events widget-for-eventbrite-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display Eventbrite Events: from n/a through <= 6.5.6.

PUBLISHED
Vendor
fullworks
Product
Display Eventbrite Events
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39534

Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

PUBLISHED
Vendor
Wp Directory Kit
Product
WP Directory Kit
Provider severity
HIGH
Conflicts
0

CVE-2026-39533

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.

PUBLISHED
Vendor
WPTasty
Product
AWP Classifieds
Provider severity
HIGH
Conflicts
0

CVE-2026-39532

Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.

PUBLISHED
Vendor
Stiofan
Product
Events Calendar for GeoDirectory
Provider severity
HIGH
Conflicts
0

CVE-2026-39531

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

PUBLISHED
Vendor
Wp Directory Kit
Product
WP Directory Kit
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39530

Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.

PUBLISHED
Vendor
SpeakOut!
Product
SpeakOut! Email Petitions
Provider severity
CRITICAL
Conflicts
0

CVE-2026-3953

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XSS), Reflected XSS. This issue affects Proticaret E-Commerce: from v5.0.0 before V 6.0.1767.1383.

PUBLISHED
Vendor
Gosoft Software Industry and Trade Ltd. Co.
Product
Proticaret E-Commerce
Provider severity
HIGH
Conflicts
0

CVE-2026-39529

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

PUBLISHED
Vendor
ThemeREX Group
Product
Elementra
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39528

Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.

PUBLISHED
Vendor
WP Delicious
Product
WP Delicious
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39527

Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

PUBLISHED
Vendor
sc Internet Vivoo
Product
WpStream
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39526

Authorization Bypass Through User-Controlled Key vulnerability in wpstream WpStream wpstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpStream: from n/a through < 4.11.2.

PUBLISHED
Vendor
wpstream
Product
WpStream
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39525

Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.

PUBLISHED
Vendor
Booking Activities Team
Product
Booking Activities
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39524

Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.

PUBLISHED
Vendor
ThemeGrill
Product
Masteriyo - LMS
Provider severity
HIGH
Conflicts
0

CVE-2026-39523

Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Solene Core
Provider severity
HIGH
Conflicts
0

CVE-2026-39522

Unauthenticated Local File Inclusion in Solene <= 3.4 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Solene
Provider severity
HIGH
Conflicts
0

CVE-2026-39521

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content nelio-content allows Server Side Request Forgery.This issue affects Nelio Content: from n/a through <= 4.3.1.

PUBLISHED
Vendor
Nelio Software
Product
Nelio Content
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39520

Missing Authorization vulnerability in weDevs weDocs wedocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weDocs: from n/a through <= 2.1.18.

PUBLISHED
Vendor
weDevs
Product
weDocs
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39519

Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.

PUBLISHED
Vendor
Ahmad
Product
GeekyBot
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39518

Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.

PUBLISHED
Vendor
EventPrime
Product
EventPrime
Provider severity
HIGH
Conflicts
0

CVE-2026-39517

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6.

PUBLISHED
Vendor
A WP Life
Product
Blog Filter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39516

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Retrieve Embedded Sensitive Data.This issue affects Nexter Blocks: from n/a through <= 4.7.0.

PUBLISHED
Vendor
POSIMYTH
Product
Nexter Blocks
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39515

Subscriber Broken Access Control in Motors < 1.4.107 versions.

PUBLISHED
Vendor
StylemixThemes
Product
Motors
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39514

Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.

PUBLISHED
Vendor
Cozmoslabs
Product
Paid Member Subscriptions
Provider severity
HIGH
Conflicts
0

CVE-2026-39513

Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.

PUBLISHED
Vendor
Easy Appointments
Product
Easy Appointments
Provider severity
HIGH
Conflicts
0

CVE-2026-39512

Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

PUBLISHED
Vendor
Paolo
Product
GeoDirectory
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39511

Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

PUBLISHED
Vendor
Jacob N. Breetvelt
Product
WP Photo Album Plus
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39510

Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.

PUBLISHED
Vendor
WP Chill
Product
Image Photo Gallery Final Tiles Grid
Provider severity
LOW
Conflicts
1

CVE-2026-3951

A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry.js of the component Error Response Handler. The manipulation of the argument ID results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
LockerProject
Product
Locker
Provider severity
MEDIUM
Conflicts
2

CVE-2026-39509

Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.

PUBLISHED
Vendor
wpWax
Product
Directorist
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39508

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-woocommerce-free allows DOM-Based XSS.This issue affects Advanced Coupons for WooCommerce Coupons: from n/a through <= 4.7.1.1.

PUBLISHED
Vendor
Josh Kohlbach
Product
Advanced Coupons for WooCommerce Coupons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39507

Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.

PUBLISHED
Vendor
Themeisle
Product
Social Slider Feed
Provider severity
HIGH
Conflicts
0

CVE-2026-39506

Missing Authorization vulnerability in Jordy Meow AI Engine (Pro) ai-engine-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Engine (Pro): from n/a through < 3.4.2.

PUBLISHED
Vendor
Jordy Meow
Product
AI Engine (Pro)
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39505

Missing Authorization vulnerability in Craig Hewitt Seriously Simple Podcasting seriously-simple-podcasting allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Seriously Simple Podcasting: from n/a through <= 3.14.2.

PUBLISHED
Vendor
Craig Hewitt
Product
Seriously Simple Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39504

Missing Authorization vulnerability in InstaWP InstaWP Connect instawp-connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects InstaWP Connect: from n/a through <= 0.1.2.5.

PUBLISHED
Vendor
InstaWP
Product
InstaWP Connect
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39503

Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.

PUBLISHED
Vendor
Awesomemotive
Product
Easy Digital Downloads
Provider severity
HIGH
Conflicts
0

CVE-2026-39502

Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

PUBLISHED
Vendor
10Web
Product
Form Maker by 10Web
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39501

Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FOX: from n/a through <= 1.4.5.

PUBLISHED
Vendor
RealMag777
Product
FOX
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39500

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.2.

PUBLISHED
Vendor
Themesflat
Product
themesflat-addons-for-elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3950

A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file libheif/sequences/track.cc of the component stsz/stts. The manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. Applying a patch is the recommended action to fix this issue. The patch available is inofficial and not approved yet.

PUBLISHED
Vendor
strukturag
Product
libheif
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-39499

Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.

PUBLISHED
Vendor
Wombat Plugins
Product
Advanced Product Fields (Product Addons) for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-39498

Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

PUBLISHED
Vendor
Yeeaddons
Product
YayMail
Provider severity
HIGH
Conflicts
0

CVE-2026-39497

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Blind SQL Injection.This issue affects FOX: from n/a through <= 1.4.5.

PUBLISHED
Vendor
RealMag777
Product
FOX
Provider severity
HIGH
Conflicts
0

CVE-2026-39496

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through <= 4.3.3.

PUBLISHED
Vendor
YayCommerce
Product
YayMail
Provider severity
HIGH
Conflicts
0

CVE-2026-39495

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.

PUBLISHED
Vendor
NSquared
Product
Simply Schedule Appointments
Provider severity
HIGH
Conflicts
0