VYPR

CVEs

347,058 total · page 334 of 6,942

  • CVE-2026-0703MedMay 2, 2026
    risk 0.35cvss 6.4epss 0.00

    The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and including, 2.23.0 due to insufficient input sanitization and output escaping on user…

  • CVE-2026-7628MedMay 2, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be…

  • CVE-2026-6817MedMay 2, 2026
    risk 0.31cvss 5.8epss 0.00

    The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter in all versions up to, and including, 6.7.1.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

  • CVE-2026-6525MedMay 2, 2026
    risk 0.29cvss 5.5epss 0.00

    IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4

  • CVE-2026-6320HigMay 2, 2026
    risk 0.42cvss 7.5epss 0.00

    The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted…

  • CVE-2026-4790MedMay 2, 2026
    risk 0.28cvss 5.4epss 0.00

    The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_svg' parameter in versions up to, and including, 4.11.70 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-4100HigMay 2, 2026
    risk 0.39cvss 7.1epss 0.00

    The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhook configuration in all versions up to, and including, 3.6.5. This is due to missing capability checks on the `wp_ajax_pmpro_stripe_create_webhook`,…

  • CVE-2026-4062HigMay 2, 2026
    risk 0.42cvss 7.5epss 0.00

    The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_ids' parameters in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameters and lack of sufficient…

  • CVE-2026-4061HigMay 2, 2026
    risk 0.42cvss 7.5epss 0.00

    The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all versions up to, and including, 1.13.18. This is due to the `SearchResults` hook explicitly calling `stripslashes_deep($_POST)` which removes WordPress magic…

  • CVE-2026-4060HigMay 2, 2026
    risk 0.42cvss 7.5epss 0.00

    The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.18. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2026-7627MedMay 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function CallToolRequestSchema of the file src/index.ts of the component sync_ea_from_file. Such manipulation of the argument ea_name leads to path traversal. The attack…

  • CVE-2026-7612MedMay 2, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the file /edit_user.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly…

  • CVE-2026-7611LowMay 2, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev of the file cameo_dev.sh of the component Firmware Update Handler. Performing a manipulation results in insufficient verification of data authenticity. The…

  • CVE-2026-7610LowMay 2, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi of the component Firmware Update. Such manipulation leads to cleartext transmission of sensitive information. The attack can be executed remotely. This attack…

  • CVE-2026-7609MedMay 2, 2026
    risk 0.41cvss 6.3epss 0.04

    A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the file /tmp/diagnostic of the component Firmware Udpate. This manipulation causes os command injection. Remote exploitation of the attack is possible. The…

  • CVE-2026-7491HigMay 2, 2026
    risk 0.53cvss 8.1epss 0.00

    School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify a specific parameter to read and modify other users' data.

  • CVE-2026-7490HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2026-7489HigMay 2, 2026
    risk 0.57cvss 8.8epss 0.00

    CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2026-5077MedMay 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.2.1 due to insufficient output escaping when rendering the_title() inside HTML attribute context in the home blog section template. This makes it…

  • CVE-2026-7608MedMay 2, 2026
    risk 0.36cvss 5.5epss 0.05

    A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic. The manipulation results in os command injection. The exploit is now public and may be used. The vendor explains: "That firmware version will only work on…

  • CVE-2026-5324HigMay 2, 2026
    risk 0.40cvss 7.2epss 0.00

    The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to, and including, 2.8.11 This is due to a combination of missing nonce verification for unauthenticated form submissions, insufficient handling of…

  • CVE-2026-4024MedMay 2, 2026
    risk 0.34cvss 5.3epss 0.01

    The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `wpr_update_form_action_meta` AJAX action in all versions up to, and including, 1.7.1056. The handler is registered on both `wp_ajax`…

  • CVE-2026-7649HigMay 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.0.60 due to insufficient escaping on the…

  • CVE-2026-7607HigMay 2, 2026
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware of the component Firmware Udpate. The manipulation of the argument str leads to buffer overflow. The attack may be initiated remotely. The vendor explains:…

  • CVE-2026-7606LowMay 2, 2026
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_firmware of the component Firmware Update Handler. Executing a manipulation of the argument dest can lead to insufficient verification of data authenticity.…

  • CVE-2026-6457MedMay 2, 2026
    risk 0.35cvss 6.5epss 0.00

    The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' parameter in all versions up to, and including, 1.13.19 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-6449MedMay 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely…

  • CVE-2026-6229HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1057. This is due to insufficient validation of user-supplied URLs in the render_csv_data() function, which can be bypassed by including…

  • CVE-2026-4650MedMay 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and including 2.0.8. This is due to missing authorization and nonce verification in the donate_action_status() AJAX handler, which is registered to be accessible to…

  • CVE-2026-2052HigMay 2, 2026
    risk 0.50cvss 8.8epss 0.01

    The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on…

  • CVE-2026-7605MedMay 2, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the…

  • CVE-2026-43058MedMay 2, 2026
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSAN warnings vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their argument structs by value, causing MSAN to report uninit-value warnings. While…

  • CVE-2026-7647HigMay 2, 2026
    risk 0.53cvss 8.1epss 0.00

    The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the attacker-controlled 'args' POST parameter within the…

  • CVE-2026-7049HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.01

    The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 via the scan_video. This makes it possible for unauthenticated attackers to make web requests to arbitrary…

  • CVE-2026-6916MedMay 2, 2026
    risk 0.42cvss 6.4epss 0.00

    The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sg_content_number_prefix' parameter in all versions up to, and including, 3.1.0 due to insufficient input…

  • CVE-2026-6812MedMay 2, 2026
    risk 0.29cvss 4.4epss 0.00

    The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via the ona_activate_child_theme. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary…

  • CVE-2026-6447MedMay 2, 2026
    risk 0.29cvss 4.4epss 0.00

    The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

  • CVE-2026-5113HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with…

  • CVE-2026-5112HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater…

  • CVE-2026-5111HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields…

  • CVE-2026-5110HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When…

  • CVE-2026-5109HigMay 2, 2026
    risk 0.47cvss 7.2epss 0.00

    The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function…

  • CVE-2026-7641HigMay 2, 2026
    risk 0.50cvss 8.8epss 0.01

    The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta…

  • CVE-2026-7604MedMay 2, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiController.java of the component OpenApi Service. Such manipulation of the argument originUrl database leads to server-side request…

  • CVE-2026-7603MedMay 2, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils.jav of the component LoadFile Endpoint. This manipulation of the argument files causes server-side request forgery. It is…

  • CVE-2026-7458CriMay 2, 2026
    risk 0.57cvss 9.8epss 0.01

    The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.0.46. This is due to the use of a loose PHP comparison operator to validate OTP codes in the "user_verification_form_wrap_process_otpLogin"…

  • CVE-2026-6963HigMay 2, 2026
    risk 0.57cvss 8.8epss 0.00

    The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access…

  • CVE-2026-6446MedMay 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to and including 1.0.4 via the 'ttp_get_accounts' AJAX action. This is due to the complete absence of authorization checks (no capability…

  • CVE-2026-4882CriMay 2, 2026
    risk 0.64cvss 9.8epss 0.01

    The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'URAF_AJAX::method_upload' function in all versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to…

  • CVE-2026-4658MedMay 2, 2026
    risk 0.42cvss 6.4epss 0.00

    The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the className, classHook, and blockId attributes in the Add to Cart block (essential-blocks/add-to-cart) in all versions up to, and…