VYPR

CVEs

378,655 total · page 502 of 7,574

  • CVE-2026-14516HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-14171MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.

  • CVE-2026-14170Jul 28, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-14169HigJul 28, 2026
    risk 0.00cvss 8.1epss 0.00

    Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could result in complete administrative unavailability of the device.

  • CVE-2026-14168HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full system access.

  • CVE-2026-14167HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization.

  • CVE-2026-13161HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack…

  • CVE-2026-12800HigJul 28, 2026
    risk 0.42cvss 7.5epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint in versions up to, and including, 6.2.0. This is due to insufficient escaping on the…

  • CVE-2026-55977LowJul 28, 2026
    risk 0.00cvss 3.3epss 0.00

    Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code and potentially displaying harmful content on the affected screen.

  • CVE-2026-15730MedJul 28, 2026
    risk 0.00cvss 6.4epss 0.00

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input…

  • CVE-2026-15673MedJul 28, 2026
    risk 0.00cvss 4.4epss 0.00

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient…

  • CVE-2026-15671MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter…

  • CVE-2026-15670MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied…

  • CVE-2026-15014CriJul 28, 2026
    risk 0.00cvss 9.8epss 0.00

    The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the…

  • CVE-2026-12741HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-11756CriJul 28, 2026
    risk 0.00cvss 10.0epss 0.00

    A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

  • CVE-2024-14041MedJul 28, 2026
    risk 0.31cvss 5.9epss 0.00

    In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and…

  • CVE-2026-6251MedJul 28, 2026
    risk 0.00cvss 6.5epss 0.00

    The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via…

  • CVE-2026-16811MedJul 28, 2026
    risk 0.00cvss 4.9epss 0.00

    The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied parameter and lack…

  • CVE-2026-16797MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key.…

  • CVE-2026-16587MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-16585HigJul 28, 2026
    risk 0.40cvss 7.2epss 0.01

    The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it…

  • CVE-2026-15136MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it…

  • CVE-2026-15012MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the…

  • CVE-2026-14926MedJul 28, 2026
    risk 0.00cvss 4.2epss 0.00

    The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its…

  • CVE-2026-14924HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

  • CVE-2026-14870HigJul 28, 2026
    risk 0.00cvss 7.1epss 0.00

    The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such…

  • CVE-2026-14821LowJul 28, 2026
    risk 0.00cvss 2.7epss 0.00

    The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.

  • CVE-2026-14819LowJul 28, 2026
    risk 0.00cvss 3.5epss 0.00

    The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against…

  • CVE-2026-14545CriJul 28, 2026
    risk 0.00cvss 9.8epss 0.00

    The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take…

  • CVE-2026-14490HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.01

    The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as…

  • CVE-2026-12124MedJul 28, 2026
    risk 0.00cvss 5.3epss 0.00

    The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST…

  • CVE-2026-17528MedJul 28, 2026
    risk 0.00cvss 6.1epss 0.00

    Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a…

  • CVE-2026-17524HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.01

    Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function,…

  • CVE-2026-66473HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

  • CVE-2026-65448MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions.

  • CVE-2026-65447HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

  • CVE-2026-65446HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

  • CVE-2026-65445MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

  • CVE-2026-65443HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

  • CVE-2026-65442HigJul 27, 2026
    risk 0.00cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

  • CVE-2026-65441HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

  • CVE-2026-65440HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

  • CVE-2026-65439HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

  • CVE-2026-65438HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

  • CVE-2026-65437HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

  • CVE-2026-61957HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

  • CVE-2026-61953HigJul 27, 2026
    risk 0.00cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

  • CVE-2026-51565MedJul 27, 2026
    risk 0.00cvss 6.1epss 0.00

    Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request

  • CVE-2025-63913HigJul 27, 2026
    risk 0.42cvss 7.5epss 0.00

    An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.