Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-22499

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Lella lella allows PHP Local File Inclusion.This issue affects Lella: from n/a through <= 1.2.

PUBLISHED
Vendor
Elated-Themes
Product
Lella
Provider severity
HIGH
Conflicts
0

CVE-2026-22498

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclusion.This issue affects Laurent: from n/a through <= 3.1.

PUBLISHED
Vendor
Elated-Themes
Product
Laurent
Provider severity
HIGH
Conflicts
0

CVE-2026-22497

Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2.

PUBLISHED
Vendor
AncoraThemes
Product
Jardi
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22496

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hypnotherapy hypnotherapy allows PHP Local File Inclusion.This issue affects Hypnotherapy: from n/a through <= 1.2.10.

PUBLISHED
Vendor
AncoraThemes
Product
Hypnotherapy
Provider severity
HIGH
Conflicts
0

CVE-2026-22495

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Greenville greenville allows PHP Local File Inclusion.This issue affects Greenville: from n/a through <= 1.3.2.

PUBLISHED
Vendor
AncoraThemes
Product
Greenville
Provider severity
HIGH
Conflicts
0

CVE-2026-22494

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Good Homes good-homes allows PHP Local File Inclusion.This issue affects Good Homes: from n/a through <= 1.3.13.

PUBLISHED
Vendor
ThemeREX
Product
Good Homes
Provider severity
HIGH
Conflicts
0

CVE-2026-22493

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gaspard gaspard allows PHP Local File Inclusion.This issue affects Gaspard: from n/a through <= 1.3.

PUBLISHED
Vendor
Elated-Themes
Product
Gaspard
Provider severity
HIGH
Conflicts
0

CVE-2026-22492

Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Docket Cache: from n/a through <= 24.07.04.

PUBLISHED
Vendor
Nawawi Jamili
Product
Docket Cache
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22491

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Reflected XSS.This issue affects My auctions allegro: from n/a through <= 3.6.35.

PUBLISHED
Vendor
wphocus
Product
My auctions allegro
Provider severity
HIGH
Conflicts
0

CVE-2026-22490

Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Landing Page Creator for WordPress LPagery: from n/a through <= 2.4.9.

PUBLISHED
Vendor
niklaslindemann
Product
Bulk Landing Page Creator for WordPress LPagery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2249

METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in the compromise of the software, granting unauthorized access to modify configuration, read and alter sensitive data, or disrupt services.

PUBLISHED
Vendor
METIS Cyberspace Technology SA
Product
METIS DFS
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22489

Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow image-slider-slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through <= 1.8.

PUBLISHED
Vendor
Wptexture
Product
Image Slider Slideshow
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22488

Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Welcome for Beaver Builder: from n/a through <= 1.0.8.

PUBLISHED
Vendor
IdeaBox Creations
Product
Dashboard Welcome for Beaver Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22487

Missing Authorization vulnerability in baqend Speed Kit baqend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Speed Kit: from n/a through <= 2.0.2.

PUBLISHED
Vendor
baqend
Product
Speed Kit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22486

Missing Authorization vulnerability in Re Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Re Gallery: from n/a through 1.18.9.

PUBLISHED
Vendor
Not asserted
Product
Re Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22485

Missing Authorization vulnerability in Ruhul Amin My Album Gallery my-album-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Album Gallery: from n/a through <= 1.0.4.

PUBLISHED
Vendor
Ruhul Amin
Product
My Album Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22484

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL Injection.This issue affects Lisfinity Core: from n/a through <= 1.5.0.

PUBLISHED
Vendor
pebas
Product
Lisfinity Core
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22483

Cross-Site Request Forgery (CSRF) vulnerability in winkm89 teachPress teachpress allows Cross Site Request Forgery.This issue affects teachPress: from n/a through <= 9.0.12.

PUBLISHED
Vendor
winkm89
Product
teachPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22482

Server-Side Request Forgery (SSRF) vulnerability in wbolt.com IMGspider imgspider allows Server Side Request Forgery.This issue affects IMGspider: from n/a through <= 2.3.12.

PUBLISHED
Vendor
wbolt.com
Product
IMGspider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22481

Missing Authorization vulnerability in Rasedul Haque Rumi BD Courier Order Ratio Checker bd-courier-order-ratio-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BD Courier Order Ratio Checker: from n/a through <= 2.0.1.

PUBLISHED
Vendor
Rasedul Haque Rumi
Product
BD Courier Order Ratio Checker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22480

Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.3.

PUBLISHED
Vendor
WebToffee
Product
Product Feed for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-2248

METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results in full system compromise, allowing unauthorized access to modify system configuration, read sensitive data, or disrupt device operations

PUBLISHED
Vendor
METIS Cyberspace Technology SA
Product
METIS WIC
Provider severity
CRITICAL
Conflicts
1

CVE-2026-22479

Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Post Submission: from n/a through <= 2.4.0.

PUBLISHED
Vendor
ThemeRuby
Product
Easy Post Submission
Provider severity
HIGH
Conflicts
0

CVE-2026-22478

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes FindAll findall allows PHP Local File Inclusion.This issue affects FindAll: from n/a through <= 1.4.

PUBLISHED
Vendor
Elated-Themes
Product
FindAll
Provider severity
HIGH
Conflicts
0

CVE-2026-22477

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Felizia felizia allows PHP Local File Inclusion.This issue affects Felizia: from n/a through <= 1.3.4.

PUBLISHED
Vendor
AncoraThemes
Product
Felizia
Provider severity
HIGH
Conflicts
0

CVE-2026-22476

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Etchy etchy allows PHP Local File Inclusion.This issue affects Etchy: from n/a through <= 1.0.

PUBLISHED
Vendor
Elated-Themes
Product
Etchy
Provider severity
HIGH
Conflicts
0

CVE-2026-22475

Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4.

PUBLISHED
Vendor
axiomthemes
Product
Estate
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22474

Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through <= 1.5.

PUBLISHED
Vendor
ThemeREX
Product
Equestrian Centre
Provider severity
CRITICAL
Conflicts
0

CVE-2026-22473

Deserialization of Untrusted Data vulnerability in designthemes Dental Clinic dental allows Object Injection.This issue affects Dental Clinic: from n/a through <= 3.7.

PUBLISHED
Vendor
designthemes
Product
Dental Clinic
Provider severity
HIGH
Conflicts
0

CVE-2026-22472

Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.9.6.

PUBLISHED
Vendor
hassantafreshi
Product
Easy Form Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22471

Deserialization of Untrusted Data vulnerability in maximsecudeal Secudeal Payments for Ecommerce secudeal-payments-for-ecommerce allows Object Injection.This issue affects Secudeal Payments for Ecommerce: from n/a through <= 1.1.

PUBLISHED
Vendor
maximsecudeal
Product
Secudeal Payments for Ecommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-22470

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real Estate fs-real-estate-plugin allows Blind SQL Injection.This issue affects FireStorm Professional Real Estate: from n/a through <= 2.7.11.

PUBLISHED
Vendor
FireStorm Plugins
Product
FireStorm Professional Real Estate
Provider severity
HIGH
Conflicts
0

CVE-2026-2247

SQL injection vulnerability (SQLi) in Clicldeu SaaS, specifically in the generation of reports, which occurs when a previously authenticated remote attacker executes a malicious payload in the URL generated after downloading the student's report card in the ‘Day-to-day’ section from the mobile application. In the URL of the generated PDF, the session token used does not expire, so it remains valid for days after its generation, and unusual characters can be entered after the ‘id_alu’ parameter,

PUBLISHED
Vendor
Clickedu
Product
SaaS platform
Provider severity
HIGH
Conflicts
0

CVE-2026-22469

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in mwtemplates DeepDigital deepdigital allows Code Injection.This issue affects DeepDigital: from n/a through <= 1.0.2.

PUBLISHED
Vendor
mwtemplates
Product
DeepDigital
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22468

Missing Authorization vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Absolute Addons For Elementor: from n/a through <= 1.0.14.

PUBLISHED
Vendor
AbsolutePlugins
Product
Absolute Addons For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22467

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mwtemplates DeepDigital deepdigital allows Reflected XSS.This issue affects DeepDigital: from n/a through <= 1.0.2.

PUBLISHED
Vendor
mwtemplates
Product
DeepDigital
Provider severity
HIGH
Conflicts
0

CVE-2026-22466

Missing Authorization vulnerability in Chandni Patel WP MapIt wp-mapit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP MapIt: from n/a through <= 3.0.3.

PUBLISHED
Vendor
Chandni Patel
Product
WP MapIt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22465

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen BuddyApp buddyapp allows Reflected XSS.This issue affects BuddyApp: from n/a through <= 1.9.2.

PUBLISHED
Vendor
SeventhQueen
Product
BuddyApp
Provider severity
HIGH
Conflicts
0

CVE-2026-22464

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows PHP Local File Inclusion.This issue affects My auctions allegro: from n/a through <= 3.6.33.

PUBLISHED
Vendor
wphocus
Product
My auctions allegro
Provider severity
HIGH
Conflicts
0

CVE-2026-22463

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.company Form to Chat App form-to-chat allows Stored XSS.This issue affects Form to Chat App: from n/a through <= 1.2.5.

PUBLISHED
Vendor
Micro.company
Product
Form to Chat App
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22462

Cross-Site Request Forgery (CSRF) vulnerability in richardevcom Add Polylang support for Customizer add-polylang-support-for-customizer allows Cross Site Request Forgery.This issue affects Add Polylang support for Customizer: from n/a through <= 1.4.5.

PUBLISHED
Vendor
richardevcom
Product
Add Polylang support for Customizer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22461

Missing Authorization vulnerability in WebAppick CTX Feed webappick-product-feed-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CTX Feed: from n/a through <= 6.6.18.

PUBLISHED
Vendor
WebAppick
Product
CTX Feed
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22460

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax FormGent formgent allows Path Traversal.This issue affects FormGent: from n/a through <= 1.7.0.

PUBLISHED
Vendor
wpWax
Product
FormGent
Provider severity
HIGH
Conflicts
0

CVE-2026-2246

A security vulnerability has been detected in AprilRobotics apriltag up to 3.4.5. Affected by this vulnerability is the function apriltag_detector_detect of the file apriltag.c. The manipulation leads to memory corruption. The attack must be carried out locally. The exploit has been disclosed publicly and may be used. The identifier of the patch is cfac2f5ce1ffe2de25967eb1ab80bc5d99fc1a61. It is suggested to install a patch to address this issue.

PUBLISHED
Vendor
AprilRobotics
Product
apriltag
Provider severity
LOW, MEDIUM
Conflicts
1

CVE-2026-22459

Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through <= 2.1.2.

PUBLISHED
Vendor
Blend Media
Product
WordPress CTA
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22458

Missing Authorization vulnerability in Mikado-Themes Wanderland wanderland allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wanderland: from n/a through <= 1.5.

PUBLISHED
Vendor
Mikado-Themes
Product
Wanderland
Provider severity
MEDIUM
Conflicts
0

CVE-2026-22457

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through <= 1.5.

PUBLISHED
Vendor
Mikado-Themes
Product
Wanderland
Provider severity
HIGH
Conflicts
0

CVE-2026-22456

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Askka askka allows PHP Local File Inclusion.This issue affects Askka: from n/a through <= 1.0.

PUBLISHED
Vendor
Elated-Themes
Product
Askka
Provider severity
HIGH
Conflicts
0

CVE-2026-22455

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thebe thebe allows Reflected XSS.This issue affects Thebe: from n/a through <= 1.3.0.

PUBLISHED
Vendor
foreverpinetree
Product
Thebe
Provider severity
HIGH
Conflicts
0

CVE-2026-22454

Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through <= 2.5.

PUBLISHED
Vendor
ThemeREX
Product
Solaris
Provider severity
CRITICAL
Conflicts
0