Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-3242

In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block.  The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.  Thanks M3dium for reporting.

PUBLISHED
Vendor
Concrete CMS
Product
Concrete CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32419

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Briano List category posts list-category-posts allows DOM-Based XSS.This issue affects List category posts: from n/a through <= 0.93.1.

PUBLISHED
Vendor
Fernando Briano
Product
List category posts
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32418

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Blind SQL Injection.This issue affects Meow Gallery: from n/a through <= 5.4.4.

PUBLISHED
Vendor
Jordy Meow
Product
Meow Gallery
Provider severity
HIGH
Conflicts
0

CVE-2026-32417

Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through < 1.18.9.

PUBLISHED
Vendor
wppochipp
Product
Pochipp
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32416

Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Poster: from n/a through <= 2.4.0.

PUBLISHED
Vendor
bPlugins
Product
PDF Poster
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32415

Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.

PUBLISHED
Vendor
Bogdan Bendziukov
Product
Squeeze
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32414

Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion.This issue affects Advanced Woo Labels: from n/a through <= 2.36.

PUBLISHED
Vendor
ILLID
Product
Advanced Woo Labels
Provider severity
HIGH
Conflicts
0

CVE-2026-32413

Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3.

PUBLISHED
Vendor
Maciej Bis
Product
Permalink Manager Lite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32412

Server-Side Request Forgery (SSRF) vulnerability in Gift Up! Gift Up Gift Cards for WordPress and WooCommerce gift-up allows Server Side Request Forgery.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through <= 3.1.7.

PUBLISHED
Vendor
Gift Up!
Product
Gift Up Gift Cards for WordPress and WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32411

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed Calendly embed-calendly-scheduling allows Stored XSS.This issue affects Embed Calendly: from n/a through <= 4.4.

PUBLISHED
Vendor
Simpma
Product
Embed Calendly
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32410

Missing Authorization vulnerability in WBW Plugins WBW Currency Switcher for WooCommerce woo-currency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WBW Currency Switcher for WooCommerce: from n/a through <= 2.2.5.

PUBLISHED
Vendor
WBW Plugins
Product
WBW Currency Switcher for WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2026-3241

In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block. An authenticated user with permissions to create or edit forms (e.g., a rogue administrator) can inject a persistent JavaScript payload into the options of a multiple-choice question (Checkbox List, Radio Buttons, or Select Box). This payload is then executed in the browser of any user who views the page containing the form. The Concrete CMS security team gave this vulnerabil

PUBLISHED
Vendor
Concrete CMS
Product
Concrete CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32409

Missing Authorization vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Forminator: from n/a through <= 1.50.2.

PUBLISHED
Vendor
WPMU DEV - Your All-in-One WordPress Platform
Product
Forminator
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32408

Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy: from n/a through <= 2.7.23.

PUBLISHED
Vendor
themefusecom
Product
Brizy
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32407

Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8.

PUBLISHED
Vendor
WPClever
Product
WPC Smart Wishlist for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32406

Missing Authorization vulnerability in WPClever WPC Product Bundles for WooCommerce woo-product-bundle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Product Bundles for WooCommerce: from n/a through <= 8.4.5.

PUBLISHED
Vendor
WPClever
Product
WPC Product Bundles for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32405

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in xtemos WoodMart woodmart allows Retrieve Embedded Sensitive Data.This issue affects WoodMart: from n/a through <= 8.3.9.

PUBLISHED
Vendor
xtemos
Product
WoodMart
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32404

Missing Authorization vulnerability in Studio99 Studio99 WP Monitor studio99-wp-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Studio99 WP Monitor: from n/a through <= 1.0.3.

PUBLISHED
Vendor
Studio99
Product
Studio99 WP Monitor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in toocheke Toocheke Companion toocheke-companion allows DOM-Based XSS.This issue affects Toocheke Companion: from n/a through <= 1.194.

PUBLISHED
Vendor
toocheke
Product
Toocheke Companion
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32402

Missing Authorization vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider by Ays: from n/a through <= 2.7.1.

PUBLISHED
Vendor
Ays Pro
Product
Image Slider by Ays
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32401

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.

PUBLISHED
Vendor
BoldGrid
Product
Client Invoicing by Sprout Invoices
Provider severity
HIGH
Conflicts
0

CVE-2026-32400

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemetechMount Boldman boldman allows PHP Local File Inclusion.This issue affects Boldman: from n/a through <= 7.7.

PUBLISHED
Vendor
ThemetechMount
Product
Boldman
Provider severity
HIGH
Conflicts
0

CVE-2026-3240

In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored XSS attack towards high-privilege accounts via the Question field. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 4.8 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Thanks minhnn42, namdi and quanlna2 from VCSLab-Viettel Cyber Security for reporting.

PUBLISHED
Vendor
Concrete CMS
Product
Concrete CMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32399

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Blind SQL Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.32.

PUBLISHED
Vendor
David Lingren
Product
Media LIbrary Assistant
Provider severity
HIGH
Conflicts
0

CVE-2026-32398

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Subrata Mal TeraWallet – For WooCommerce woo-wallet allows Leveraging Race Conditions.This issue affects TeraWallet – For WooCommerce: from n/a through <= 1.5.15.

PUBLISHED
Vendor
Subrata Mal
Product
TeraWallet – For WooCommerce
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32397

Missing Authorization vulnerability in YMC Filter & Grids ymc-smart-filter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Filter & Grids: from n/a through <= 3.5.1.

PUBLISHED
Vendor
YMC
Product
Filter & Grids
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32396

Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13.

PUBLISHED
Vendor
RadiusTheme
Product
Team
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32395

Missing Authorization vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.6.

PUBLISHED
Vendor
Xpro
Product
Xpro Addons For Beaver Builder – Lite
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32394

Missing Authorization vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Capabilities: from n/a through <= 2.31.0.

PUBLISHED
Vendor
PublishPress
Product
PublishPress Capabilities
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32393

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly Theme Addons greenly-addons allows PHP Local File Inclusion.This issue affects Greenly Theme Addons: from n/a through < 8.2.

PUBLISHED
Vendor
Creatives_Planet
Product
Greenly Theme Addons
Provider severity
HIGH
Conflicts
0

CVE-2026-32392

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly greenly allows PHP Local File Inclusion.This issue affects Greenly: from n/a through <= 8.1.

PUBLISHED
Vendor
Creatives_Planet
Product
Greenly
Provider severity
HIGH
Conflicts
0

CVE-2026-32391

Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4.

PUBLISHED
Vendor
linethemes
Product
SmartFix
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32390

Missing Authorization vulnerability in linethemes Nanosoft nanosoft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Nanosoft: from n/a through < 1.3.2.

PUBLISHED
Vendor
linethemes
Product
Nanosoft
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3239

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PUBLISHED
Vendor
wpchill
Product
Strong Testimonials
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32389

Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2.

PUBLISHED
Vendor
Linethemes
Product
NanoCare
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32388

Missing Authorization vulnerability in linethemes GLB glb allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GLB: from n/a through <= 1.2.2.

PUBLISHED
Vendor
linethemes
Product
GLB
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32387

Missing Authorization vulnerability in Noor Alam Checkout for PayPal checkout-for-paypal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Checkout for PayPal: from n/a through <= 1.0.46.

PUBLISHED
Vendor
Noor Alam
Product
Checkout for PayPal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32386

Missing Authorization vulnerability in EnvoThemes Envo Extra envo-extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Envo Extra: from n/a through <= 1.9.13.

PUBLISHED
Vendor
EnvoThemes
Product
Envo Extra
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32385

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 6.0.7.6.

PUBLISHED
Vendor
Metagauss
Product
RegistrationMagic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32384

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpBookingly service-booking-manager allows PHP Local File Inclusion.This issue affects WpBookingly: from n/a through <= 1.2.9.

PUBLISHED
Vendor
magepeopleteam
Product
WpBookingly
Provider severity
HIGH
Conflicts
0

CVE-2026-32383

Missing Authorization vulnerability in raratheme Ridhi ridhi allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ridhi: from n/a through <= 1.1.2.

PUBLISHED
Vendor
raratheme
Product
Ridhi
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32382

Missing Authorization vulnerability in raratheme Digital Download digital-download allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Digital Download: from n/a through <= 1.1.4.

PUBLISHED
Vendor
raratheme
Product
Digital Download
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32381

Missing Authorization vulnerability in raratheme App Landing Page app-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Landing Page: from n/a through <= 1.2.2.

PUBLISHED
Vendor
raratheme
Product
App Landing Page
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32380

Missing Authorization vulnerability in raratheme Numinous numinous allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Numinous: from n/a through <= 1.3.0.

PUBLISHED
Vendor
raratheme
Product
Numinous
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3238

A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protocol handlers for certain request types did not properly validate incoming packets, allowing an unauthenticated remote attacker to trigger a NULL pointer dereference and crash the WINS service using specially crafted UDP packets.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6
Provider severity
HIGH
Conflicts
1

CVE-2026-32379

Missing Authorization vulnerability in raratheme Rara Academic rara-academic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rara Academic: from n/a through <= 1.2.2.

PUBLISHED
Vendor
raratheme
Product
Rara Academic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32378

Missing Authorization vulnerability in raratheme Book Landing Page book-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Landing Page: from n/a through <= 1.2.7.

PUBLISHED
Vendor
raratheme
Product
Book Landing Page
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32377

Missing Authorization vulnerability in raratheme Pranayama Yoga pranayama-yoga allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pranayama Yoga: from n/a through <= 1.2.2.

PUBLISHED
Vendor
raratheme
Product
Pranayama Yoga
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32376

Missing Authorization vulnerability in raratheme Kalon kalon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kalon: from n/a through <= 1.2.9.

PUBLISHED
Vendor
raratheme
Product
Kalon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32375

Missing Authorization vulnerability in raratheme Travel Diaries travel-diaries allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Diaries: from n/a through <= 1.2.4.

PUBLISHED
Vendor
raratheme
Product
Travel Diaries
Provider severity
MEDIUM
Conflicts
0