VYPR

CVEs

382,346 total · page 279 of 7,647

  • CVE-2026-79991HigSep 2, 2026
    risk 0.39cvss —epss 0.01

    Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed…

  • CVE-2026-79990HigSep 2, 2026
    risk 0.50cvss —epss 0.00

    Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed…

  • CVE-2026-79989HigSep 2, 2026
    risk 0.50cvss —epss 0.00

    The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which…

  • CVE-2026-78609MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate…

  • CVE-2026-78604HigSep 2, 2026
    risk 0.44cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created…

  • CVE-2026-78602MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the…

  • CVE-2026-78601MedSep 2, 2026
    risk 0.29cvss 5.5epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly…

  • CVE-2026-78600LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to…

  • CVE-2026-78599MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a…

  • CVE-2026-78598MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single…

  • CVE-2026-78594MedSep 2, 2026
    risk 0.25cvss 4.9epss 0.01

    Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that…

  • CVE-2026-78591MedSep 2, 2026
    risk 0.34cvss 6.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a…

  • CVE-2026-78590HigSep 2, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause…

  • CVE-2026-78588MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the…

  • CVE-2026-78587LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to…

  • CVE-2026-78586MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded…

  • CVE-2026-78584MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a…

  • CVE-2026-78153MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.

  • CVE-2026-77794MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the…

  • CVE-2026-77793MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.

  • CVE-2026-77009CriSep 2, 2026
    risk 0.64cvss 9.9epss 0.01

    The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.

  • CVE-2026-4357CriSep 2, 2026
    risk 0.65cvss 10.0epss 0.01

    The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

  • CVE-2026-2811MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.

  • CVE-2026-2688MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access…

  • CVE-2026-19698LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users…

  • CVE-2026-17563MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately…

  • CVE-2026-14326LowSep 2, 2026
    risk 0.25cvss 3.8epss 0.00

    The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

  • CVE-2026-14255MedSep 2, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.…

  • CVE-2026-10821MedSep 2, 2026
    risk 0.43cvss 6.6epss 0.01

    The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with…

  • CVE-2025-9314CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

  • CVE-2025-8945MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

  • CVE-2025-15692LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2025-15490MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

  • CVE-2025-15489MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content

  • CVE-2025-15485HigSep 2, 2026
    risk 0.53cvss 8.2epss 0.00

    The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc

  • CVE-2025-15481MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.

  • CVE-2025-13398Sep 2, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability in the DesignThemes LMS WordPress plugin. All CVE users should reference CVE-2025-13542 instead of this ID.

  • CVE-2024-7956HigSep 2, 2026
    risk 0.49cvss —epss 0.00

    A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.

  • CVE-2024-3773MedSep 2, 2026
    risk 0.38cvss 5.9epss 0.00

    The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…

  • CVE-2023-3360LowSep 2, 2026
    risk 0.21cvss 3.3epss 0.00

    The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2026-81269MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.

  • CVE-2026-81205MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.

  • CVE-2026-81201MedSep 2, 2026
    risk 0.33cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.3.

  • CVE-2026-81168LowSep 2, 2026
    risk 0.17cvss 3.7epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.

  • CVE-2026-81167MedSep 2, 2026
    risk 0.24cvss 4.8epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0 to 1.0.25.

  • CVE-2026-81166MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Missing Authorization vulnerability in Drupal Digital Signage Framework allows Forceful Browsing. This issue affects Digital Signage Framework versions: from 0.0.0 to 2.6.1.

  • CVE-2026-81165MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Incorrect Authorization vulnerability in Drupal Blazy allows Forceful Browsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.

  • CVE-2026-81164MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Missing Authorization vulnerability in Drupal Entity PDF allows Forceful Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.

  • CVE-2026-81162MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forceful Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1.

  • CVE-2026-81161LowSep 2, 2026
    risk 0.21cvss 3.3epss 0.00

    Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalation. This issue affects Content Moderation Notifications versions: from 0.0.0 to 3.9.0.