CVE search
400,995 resultsCVE-2026-79618MEDIUMWP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated FormEPSS 0.2%CVE-2026-1661MEDIUMWP Mail Logging < 1.17.0 - Unauthenticated HTML InjectionEPSS 0.2%CVE-2026-13413MEDIUMCMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL MatchEPSS 0.2%CVE-2026-16001HIGHIesEngine stream-mode MAC forgery via length-dependent KDF splitEPSS 0.2%CVE-2026-16000HIGHKCcmBlockCipher (DSTU 7624 CCM) tag not bound to nonce when no associated data is usedEPSS 0.3%CVE-2026-15999HIGHAES-CCM decryption accepts zero or out-of-range tag length, bypassing authenticationEPSS 0.2%CVE-2026-102565HIGHBA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' ParameterEPSS 0.3%CVE-2026-93029CRITICALThere is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.EPSS 0.4%CVE-2026-93697CRITICALThere is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.EPSS 0.4%CVE-2026-93698CRITICALInsufficient validation allows arbitrary commands to be executed via the Multilang adminbin.EPSS 0.5%CVE-2026-97318MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' ParameterEPSS 0.1%CVE-2026-97317MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway PageEPSS 0.1%CVE-2026-94298MEDIUMBuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content ParameterEPSS 0.2%CVE-2026-91023LOWMotors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featuredEPSS 0.1%CVE-2026-91022MEDIUMMotors < 1.4.124 - Listing Manager+ Stored XSS via Badge ColorEPSS 0.2%CVE-2026-85016MEDIUMUnlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library ParameterEPSS 0.2%CVE-2026-91828HIGHOMGF < 6.3.11 - Unauthenticated DoS via do_optimizeEPSS 0.2%CVE-2026-13718MEDIUMTabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab ContentEPSS 0.2%CVE-2026-90988MEDIUMRequest a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenumEPSS 0.1%CVE-2026-85004MEDIUMPopup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connectEPSS 0.1%