CVE search
401,036 resultsCVE-2026-85235HIGHForminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea FieldEPSS 0.3%CVE-2026-92244HIGHPDF Invoices & Packing Slips for WooCommerce <= 5.16.1 - Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company FieldsEPSS 0.3%CVE-2026-15983HIGHSuper Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' ParameterEPSS 0.5%CVE-2026-90992MEDIUMRedux Framework <= 4.5.14 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media FieldEPSS 0.2%CVE-2026-100179MEDIUMCalculated Fields Form <= 5.5.1.3 - Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices()EPSS 0.2%CVE-2026-14995HIGHAutoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI PathEPSS 0.3%CVE-2026-103655CRITICALMISP TOTP Code Replay Allows Duplicate Authentication Within Validity PeriodEPSS 0.3%CVE-2026-78249MEDIUMA path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 EPSS 0.2%CVE-2026-19807HIGHByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP ToolEPSS 0.4%CVE-2026-15989CRITICALSuper Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' ParameterEPSS 0.3%CVE-2026-75957CRITICALUltimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' ParameterEPSS 0.6%CVE-2026-19902MEDIUMAd Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)EPSS 0.3%CVE-2026-93882HIGHLearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' ParameterEPSS 0.4%CVE-2026-89047MEDIUMSocial Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URLEPSS 0.3%CVE-2026-103651HIGHMISP HOTP Token Replay via Stale Session-Cached Counter Allows Second-Factor Authentication BypassEPSS 0.2%CVE-2025-41753CRITICALPath traversal in dynamically created BACnet File ObjectsEPSS 0.6%CVE-2026-103544MEDIUMdatadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong sessionEPSS 0.2%CVE-2026-96255HIGHPayments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via Debug LogEPSS 0.3%CVE-2026-96200MEDIUMPayments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Payment CallbackEPSS 0.2%CVE-2026-96173MEDIUMPayments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOREPSS 0.2%