Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-27404

Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.

PUBLISHED
Vendor
Designthemes
Product
LMS
Provider severity
HIGH
Conflicts
0

CVE-2026-27403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.

PUBLISHED
Vendor
NerdPress
Product
Hubbub Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27402

Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.

PUBLISHED
Vendor
Designthemes
Product
Kids Life | Children School WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-27400

Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.

PUBLISHED
Vendor
Ovatheme
Product
BookPro
Provider severity
HIGH
Conflicts
0

CVE-2026-2740

Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.

PUBLISHED
Vendor
Zohocorp, Zohocorp, Zohocorp
Product
ManageEngine ADSelfService Plus, ManageEngine RecoveryManager Plus, ManageEngine DataSecurity Plus
Provider severity
HIGH
Conflicts
1

CVE-2026-27399

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

PUBLISHED
Vendor
WebWizards
Product
MarketKing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27398

Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.

PUBLISHED
Vendor
WP Chill
Product
RSVP and Event Management
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27397

Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Really Simple Security Pro: from n/a through 9.5.4.0.

PUBLISHED
Vendor
Really Simple Plugins B.V.
Product
Really Simple Security Pro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27396

Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6.

PUBLISHED
Vendor
e-plugins
Product
Directory Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-27395

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

PUBLISHED
Vendor
Schiocco
Product
Support Board
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27393

Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through 1.7.6.

PUBLISHED
Vendor
Tobias
Product
CF7 WOW Styler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27392

Contributor Broken Access Control in uListing <= 2.2.0 versions.

PUBLISHED
Vendor
Stylemix
Product
uListing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27391

Subscriber Broken Access Control in uListing <= 2.2.0 versions.

PUBLISHED
Vendor
Stylemix
Product
uListing
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27390

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.

PUBLISHED
Vendor
designthemes
Product
WeDesignTech Ultimate Booking Addon
Provider severity
HIGH
Conflicts
0

CVE-2026-2739

This affects versions of the package bn.js before 5.2.3. Calling maskn(0) on any BN instance corrupts the internal state, causing toString(), divmod(), and other methods to enter an infinite loop, hanging the process indefinitely.

PUBLISHED
Vendor
n/a
Product
bn.js
Provider severity
MEDIUM
Conflicts
1

CVE-2026-27389

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1.

PUBLISHED
Vendor
designthemes
Product
WeDesignTech Ultimate Booking Addon
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27388

Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Booking Manager: from n/a through <= 2.0.

PUBLISHED
Vendor
designthemes
Product
DesignThemes Booking Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-27387

Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.26.

PUBLISHED
Vendor
Designinvento
Product
DirectoryPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27386

Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Directory Addon: from n/a through <= 1.8.

PUBLISHED
Vendor
designthemes
Product
DesignThemes Directory Addon
Provider severity
HIGH
Conflicts
0

CVE-2026-27385

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio designthemes-portfolio allows Reflected XSS.This issue affects DesignThemes Portfolio: from n/a through <= 1.3.

PUBLISHED
Vendor
designthemes
Product
DesignThemes Portfolio
Provider severity
HIGH
Conflicts
0

CVE-2026-27384

Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1.

PUBLISHED
Vendor
BoldGrid
Product
W3 Total Cache
Provider severity
CRITICAL
Conflicts
0

CVE-2026-27383

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Metro metro allows PHP Local File Inclusion.This issue affects Metro: from n/a through <= 2.13.

PUBLISHED
Vendor
RadiusTheme
Product
Metro
Provider severity
HIGH
Conflicts
0

CVE-2026-27382

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro metro allows DOM-Based XSS.This issue affects Metro: from n/a through <= 2.13.

PUBLISHED
Vendor
RadiusTheme
Product
Metro
Provider severity
HIGH
Conflicts
0

CVE-2026-27381

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through <= 1.3.15.

PUBLISHED
Vendor
thembay
Product
Aora
Provider severity
HIGH
Conflicts
0

CVE-2026-2738

Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet

PUBLISHED
Vendor
OpenVPN
Product
ovpn-dco-win
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27379

Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.

PUBLISHED
Vendor
NextScripts
Product
NextScripts
Provider severity
HIGH
Conflicts
0

CVE-2026-27377

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

PUBLISHED
Vendor
axiomthemes
Product
QuickCal - Appointment Booking Calendar for WordPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27376

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Claue - Clean, Minimal Elementor WooCommerce Theme claue allows Reflected XSS.This issue affects Claue - Clean, Minimal Elementor WooCommerce Theme: from n/a through <= 2.2.7.

PUBLISHED
Vendor
JanStudio
Product
Claue - Clean, Minimal Elementor WooCommerce Theme
Provider severity
HIGH
Conflicts
0

CVE-2026-27375

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Gecko gecko allows Reflected XSS.This issue affects Gecko: from n/a through <= 1.9.8.

PUBLISHED
Vendor
JanStudio
Product
Gecko
Provider severity
HIGH
Conflicts
0

CVE-2026-27374

Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Order Details: from n/a through <= 3.1.

PUBLISHED
Vendor
vanquish
Product
WooCommerce Order Details
Provider severity
HIGH
Conflicts
0

CVE-2026-27373

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome tablesome allows Blind SQL Injection.This issue affects Tablesome: from n/a through <= 1.2.3.

PUBLISHED
Vendor
Essekia
Product
Tablesome
Provider severity
HIGH
Conflicts
0

CVE-2026-27372

Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

PUBLISHED
Vendor
Pepro Dev. Group
Product
PeproDev Ultimate Invoice
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27370

Insertion of Sensitive Information Into Sent Data vulnerability in Premio Chaty chaty allows Retrieve Embedded Sensitive Data.This issue affects Chaty: from n/a through <= 3.5.1.

PUBLISHED
Vendor
Premio
Product
Chaty
Provider severity
HIGH
Conflicts
0

CVE-2026-2737

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

PUBLISHED
Vendor
Progress Software
Product
Flowmon
Provider severity
HIGH
Conflicts
0

CVE-2026-27369

Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through <= 1.3.6.

PUBLISHED
Vendor
BoldThemes
Product
Celeste
Provider severity
HIGH
Conflicts
0

CVE-2026-27368

Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.8.

PUBLISHED
Vendor
SeedProd
Product
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27367

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through < 3.4.5.

PUBLISHED
Vendor
ThemeGoods
Product
Musico
Provider severity
HIGH
Conflicts
0

CVE-2026-27366

Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

PUBLISHED
Vendor
MainWP
Product
MainWP Child
Provider severity
HIGH
Conflicts
0

CVE-2026-27363

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Stored XSS.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6.

PUBLISHED
Vendor
kamleshyadav
Product
WP Bakery Autoresponder Addon
Provider severity
HIGH
Conflicts
0

CVE-2026-27362

Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6.

PUBLISHED
Vendor
kamleshyadav
Product
WP Bakery Autoresponder Addon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27361

Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.1.

PUBLISHED
Vendor
WebCodingPlace
Product
Responsive Posts Carousel Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-27360

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Stored XSS.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.38.

PUBLISHED
Vendor
10Web
Product
Photo Gallery by 10Web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2736

Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL containing the ‘q’ parameter in ‘/search/index.html’. This vulnerability can be exploited to steal sensitive user information such as session cookies, or to perform actions while impersonating the user.

PUBLISHED
Vendor
Alkacon
Product
OpenCms
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27359

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Awa Plugins awa-plugins allows Reflected XSS.This issue affects Awa Plugins: from n/a through <= 1.4.4.

PUBLISHED
Vendor
fox-themes
Product
Awa Plugins
Provider severity
HIGH
Conflicts
0

CVE-2026-27358

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through < 3.9.5.

PUBLISHED
Vendor
ThemeGoods
Product
Architecturer
Provider severity
HIGH
Conflicts
0

CVE-2026-27357

Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.

PUBLISHED
Vendor
Cornel Raiu
Product
WP Search Analytics
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27355

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

PUBLISHED
Vendor
metaphorcreations
Product
Ditty
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27354

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows Stored XSS.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through <= 5.0.

PUBLISHED
Vendor
WebCodingPlace
Product
WooCommerce Coming Soon Product with Countdown
Provider severity
MEDIUM
Conflicts
0

CVE-2026-27353

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand News grandnews allows Reflected XSS.This issue affects Grand News: from n/a through <= 3.4.3.

PUBLISHED
Vendor
ThemeGoods
Product
Grand News
Provider severity
HIGH
Conflicts
0

CVE-2026-27352

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through < 2.2.5.

PUBLISHED
Vendor
ThemeGoods
Product
Starto
Provider severity
HIGH
Conflicts
0