Количество 374 083
Количество 374 083
CVE-2026-65532
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65531
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65530
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-6552
Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.
CVE-2026-65529
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
CVE-2026-65528
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
CVE-2026-65527
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65526
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.
CVE-2026-65525
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.
CVE-2026-65524
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.
CVE-2026-65523
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.
CVE-2026-65522
Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-65521
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-65520
Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CVE-2026-6551
The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-65519
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.
CVE-2026-65518
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-65517
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-65516
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65515
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65532 Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | CVSS3: 7.6 | 0% Низкий | 16 дней назад | |
CVE-2026-65531 Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | CVSS3: 4.8 | 0% Низкий | 16 дней назад | |
CVE-2026-65530 Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-6552 Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected. | около 2 месяцев назад | |||
CVE-2026-65529 Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65528 Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65527 Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65526 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1. | CVSS3: 8.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65525 Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65524 Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. | CVSS3: 4.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65523 Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions. | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
CVE-2026-65522 Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65521 Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65520 Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | CVSS3: 9.3 | 0% Низкий | 2 дня назад | |
CVE-2026-6551 The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-65519 Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65518 Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65517 Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65516 Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | CVSS3: 7.2 | 0% Низкий | 16 дней назад | |
CVE-2026-65515 Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу