Количество 374 083
Количество 374 083
CVE-2026-65514
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
CVE-2026-65513
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65512
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
CVE-2026-65511
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-65510
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-6550
Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.
CVE-2026-65509
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-65508
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65507
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
CVE-2026-65506
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
CVE-2026-65505
Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65504
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVE-2026-65503
Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-65502
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
CVE-2026-65501
Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.
CVE-2026-65500
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVE-2026-6549
The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2026-65499
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions.
CVE-2026-65498
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
CVE-2026-65497
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65514 Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65513 Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65512 Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4. | CVSS3: 5.4 | 0% Низкий | 16 дней назад | |
CVE-2026-65511 Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-65510 Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | CVSS3: 7.1 | 0% Низкий | 16 дней назад | |
CVE-2026-6550 Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above. | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
CVE-2026-65509 Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65508 Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | CVSS3: 9.3 | 0% Низкий | 2 дня назад | |
CVE-2026-65507 Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. | CVSS3: 9.8 | 0% Низкий | 2 дня назад | |
CVE-2026-65506 Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65505 Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65504 Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
CVE-2026-65503 Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65502 Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. | CVSS3: 5.3 | 0% Низкий | 2 дня назад | |
CVE-2026-65501 Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65500 Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions. | CVSS3: 7.5 | 0% Низкий | 16 дней назад | |
CVE-2026-6549 The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes in all versions up to, and including, 0.7.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-65499 Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
CVE-2026-65498 Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | CVSS3: 5.3 | 0% Низкий | 16 дней назад | |
CVE-2026-65497 Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | CVSS3: 7.2 | 0% Низкий | 16 дней назад |
Уязвимостей на страницу