Количество 373 570
Количество 373 570
CVE-2026-65562
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
CVE-2026-65561
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
CVE-2026-6555
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file.
CVE-2026-65558
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
CVE-2026-65557
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
CVE-2026-65550
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65540
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-6553
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0.
CVE-2026-65539
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65536
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65535
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65534
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65533
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65532
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65531
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65530
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-6552
Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.
CVE-2026-65529
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65562 Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-65561 Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-6555 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-65558 Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | CVSS3: 5.4 | 0% Низкий | 12 дней назад | |
CVE-2026-65557 Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | CVSS3: 5.9 | 0% Низкий | 12 дней назад | |
CVE-2026-65550 Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | CVSS3: 5.9 | 0% Низкий | 16 дней назад | |
CVE-2026-65540 Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-6553 Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and user_settings fields of the be_users database table. This issue affects TYPO3 CMS version 14.2.0. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-65539 Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-65538 Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | CVSS3: 5.9 | 0% Низкий | 16 дней назад | |
CVE-2026-65537 Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65536 Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65535 Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65534 Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | CVSS3: 5.9 | 0% Низкий | 16 дней назад | |
CVE-2026-65533 Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65532 Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | CVSS3: 7.6 | 0% Низкий | 16 дней назад | |
CVE-2026-65531 Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | CVSS3: 4.8 | 0% Низкий | 16 дней назад | |
CVE-2026-65530 Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-6552 Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected. | около 2 месяцев назад | |||
CVE-2026-65529 Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад |
Уязвимостей на страницу