CVE search
400,935 resultsCVE-2026-103426HIGHRelevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' ParameterEPSS 0.2%CVE-2026-96566HIGHNewsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field ParameterEPSS 0.3%CVE-2026-102002LOWOtter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard WidgetEPSS 0.3%CVE-2026-12951MEDIUMMultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' ParameterEPSS 0.3%CVE-2026-100182HIGHDownload Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin EditorEPSS 0.3%CVE-2026-97641HIGHRelevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment ContentEPSS 0.2%CVE-2026-102772HIGHCMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' FieldEPSS 0.3%CVE-2026-95817HIGHDoFollow Case by Case <= 3.6.0 - Unauthenticated Stored Cross-Site Scripting via Comment ContentEPSS 0.2%CVE-2026-97336HIGHCMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scripting via 'file_list' Field TypeEPSS 0.3%CVE-2026-93880MEDIUMGreenshift <= 13.2.0 - Reflected Cross-Site Scripting via '{{GET:}}' Dynamic PlaceholderEPSS 0.2%CVE-2026-96567HIGHMW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Site Scripting via 'post_id' Parameter (via stored form-submitted post meta)EPSS 0.3%CVE-2026-96578HIGHGSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-Site Scripting via Comment ContentEPSS 0.3%CVE-2026-97663HIGHCustomer Reviews for WooCommerce <= 5.122.0 - Unauthenticated Stored Cross-Site Scripting via Comment Author NameEPSS 0.2%CVE-2026-17508MEDIUMPassword-based KDF cost parameters honoured unbounded from untrusted input across the remaining PBE entry pointsEPSS 0.4%CVE-2026-17507HIGHMLS membership checks compare a uint32 leaf_index as signed, admitting an out-of-range senderEPSS 0.3%CVE-2026-103604HIGHQuadratic-time escaping when converting X.509 distinguished names to stringsEPSS 0.3%CVE-2026-103603HIGHUnbounded HSS public key level count allows huge array allocation during signature verificationEPSS 0.4%CVE-2026-103602HIGHName constraints bypass via trailing dot in rfc822Name, dNSName and URI hostsEPSS 0.2%CVE-2026-103601HIGHCcmBlockCipher and KCcmBlockCipher leave unverified plaintext in the output buffer after a failed tag checkEPSS 0.3%CVE-2026-103600HIGHUnbounded ASN.1 nesting depth causes process-terminating stack overflowEPSS 0.3%