Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-6550

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

PUBLISHED
Vendor
AWS
Product
AWS Encryption SDK for Python
Provider severity
MEDIUM
Conflicts
1

CVE-2026-65499

Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.

PUBLISHED
Vendor
Pepro Dev. Group
Product
PeproDev Ultimate Invoice
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65498

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

PUBLISHED
Vendor
Complianz
Product
Complianz
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65497

Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

PUBLISHED
Vendor
Complianz
Product
Complianz
Provider severity
HIGH
Conflicts
0

CVE-2026-65496

Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.

PUBLISHED
Vendor
Complianz
Product
Complianz
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65495

Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.

PUBLISHED
Vendor
Dokan Multivendor Plugin
Product
Dokan Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-65494

Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.

PUBLISHED
Vendor
Dokan
Product
Dokan Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-65493

Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.

PUBLISHED
Vendor
Dokan
Product
Dokan Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-65492

Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.

PUBLISHED
Vendor
Dokan WordPress Plugin
Product
Dokan Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-65491

Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.

PUBLISHED
Vendor
Jonathan Daggerhart
Product
Query Wrangler
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65490

Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

PUBLISHED
Vendor
mischiefmarmot
Product
Create by Mediavine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-6549

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user

PUBLISHED
Vendor
goback2
Product
Logo Manager For Enamad
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65489

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

PUBLISHED
Vendor
LA-Studio
Product
LA-Studio Element Kit for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65488

Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

PUBLISHED
Vendor
LA-Studio
Product
LA-Studio Element Kit for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-65487

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

PUBLISHED
Vendor
ThemeGoods
Product
Photography
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65486

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

PUBLISHED
Vendor
Bastien Ho
Product
Event post
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65485

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

PUBLISHED
Vendor
Daniel Iser
Product
Content Control
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65484

Contributor Broken Access Control in Style Kits <= 2.6.5 versions.

PUBLISHED
Vendor
AnalogWP
Product
Style Kits
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65483

Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.

PUBLISHED
Vendor
hashthemes
Product
HashThemes Demo Importer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65482

Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

PUBLISHED
Vendor
LA-Studio
Product
LA-Studio Element Kit for Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65481

Contributor Local File Inclusion in Vino <= 1.9 versions.

PUBLISHED
Vendor
Elated-Themes
Product
Vino
Provider severity
HIGH
Conflicts
0

CVE-2026-65480

Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.

PUBLISHED
Vendor
CodexThemes
Product
TheGem
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65479

Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.

PUBLISHED
Vendor
MVP Themes
Product
Reviewer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65478

Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.

PUBLISHED
Vendor
CridioStudio
Product
ListingPro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65477

Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.

PUBLISHED
Vendor
Select-Themes
Product
Tonda Core
Provider severity
HIGH
Conflicts
0

CVE-2026-65476

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

PUBLISHED
Vendor
uxper
Product
Civi
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65475

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.

PUBLISHED
Vendor
WP Chill
Product
Modula Image Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65474

Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

PUBLISHED
Vendor
WPManageNinja
Product
Ninja Tables
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65473

Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.

PUBLISHED
Vendor
Nexcess
Product
Virtue/Ascend/Pinnacle Toolkit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65472

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

PUBLISHED
Vendor
Kit
Product
Kit (formerly ConvertKit)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65471

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

PUBLISHED
Vendor
Avada Studio
Product
Avada Core
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65470

Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.

PUBLISHED
Vendor
WPManageNinja
Product
Fluent Support
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65469

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

PUBLISHED
Vendor
Strategy11 Team
Product
AWP Classifieds
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65468

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

PUBLISHED
Vendor
Crocoblock. Jetimpex Inc.
Product
JetBooking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65467

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

PUBLISHED
Vendor
Crocoblock. Jetimpex Inc.
Product
JetEngine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65466

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

PUBLISHED
Vendor
Crocoblock. Jetimpex Inc.
Product
JetBooking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65465

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

PUBLISHED
Vendor
Crocoblock. Jetimpex Inc.
Product
JetElements For Elementor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65464

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

PUBLISHED
Vendor
Nexcess
Product
GiveWP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65463

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

PUBLISHED
Vendor
masteriyo
Product
Masteriyo - LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65462

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

PUBLISHED
Vendor
Uncanny Owl
Product
Uncanny Automator
Provider severity
HIGH
Conflicts
0

CVE-2026-65461

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

PUBLISHED
Vendor
Webの相談所
Product
Really Simple CSV Importer
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65460

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

PUBLISHED
Vendor
zarinpal
Product
Zarinpal Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65458

Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.

PUBLISHED
Vendor
Chouby
Product
Polylang
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65457

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

PUBLISHED
Vendor
yoomoney
Product
ЮKassa для WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65456

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

PUBLISHED
Vendor
PickPlugins
Product
Product Slider for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65455

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

PUBLISHED
Vendor
MapSVG
Product
MapSVG
Provider severity
CRITICAL
Conflicts
0

CVE-2026-65454

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

PUBLISHED
Vendor
ExpressTech Systems
Product
Quiz And Survey Master
Provider severity
HIGH
Conflicts
0

CVE-2026-65453

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

PUBLISHED
Vendor
motov.net
Product
Ebook Store
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65452

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

PUBLISHED
Vendor
motov.net
Product
Ebook Store
Provider severity
MEDIUM
Conflicts
0

CVE-2026-65451

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

PUBLISHED
Vendor
RomanCode
Product
MapSVG
Provider severity
HIGH
Conflicts
0