Количество 373 570
Количество 373 570
CVE-2026-65528
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
CVE-2026-65527
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65526
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.
CVE-2026-65525
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65524
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65522
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-65521
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-6551
The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-65519
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-65518
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-65516
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65514
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65512
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
CVE-2026-65511
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-65510
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-6550
Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.
CVE-2026-65506
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
CVE-2026-65505
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65503
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65501
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65528 Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65527 Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65526 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1. | CVSS3: 8.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65525 Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65524 Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65522 Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65521 Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-6551 The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-65519 Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65518 Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65516 Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | CVSS3: 7.2 | 0% Низкий | 16 дней назад | |
CVE-2026-65514 Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65512 Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4. | CVSS3: 5.4 | 0% Низкий | 16 дней назад | |
CVE-2026-65511 Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-65510 Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-6550 Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above. | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-65506 Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65505 Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65503 Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65501 Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад |
Уязвимостей на страницу