CVE search

401,007 results
CVE-2026-93697CRITICALThere is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.EPSS 0.4%CVE-2026-93698CRITICALInsufficient validation allows arbitrary commands to be executed via the Multilang adminbin.EPSS 0.5%CVE-2026-97318MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' ParameterEPSS 0.1%CVE-2026-97317MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway PageEPSS 0.1%CVE-2026-94298MEDIUMBuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content ParameterEPSS 0.2%CVE-2026-91023LOWMotors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featuredEPSS 0.1%CVE-2026-91022MEDIUMMotors < 1.4.124 - Listing Manager+ Stored XSS via Badge ColorEPSS 0.2%CVE-2026-85016MEDIUMUnlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library ParameterEPSS 0.2%CVE-2026-91828HIGHOMGF < 6.3.11 - Unauthenticated DoS via do_optimizeEPSS 0.2%CVE-2026-13718MEDIUMTabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab ContentEPSS 0.2%CVE-2026-90988MEDIUMRequest a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenumEPSS 0.1%CVE-2026-85004MEDIUMPopup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connectEPSS 0.1%CVE-2026-81740MEDIUMPaytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment CallbackEPSS 0.1%CVE-2026-15896CRITICALSuper Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path ParameterEPSS 0.9%CVE-2026-78471MEDIUMAutoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author NameEPSS 0.2%CVE-2026-92174HIGHSiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' ParameterEPSS 0.6%CVE-2026-90438HIGHNinja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field SubmissionEPSS 0.3%CVE-2026-15897HIGHSuper Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & LoginEPSS 0.3%CVE-2026-92820HIGHNinja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File UploadEPSS 0.5%CVE-2026-84925MEDIUMAvada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' ParameterEPSS 0.2%