CVE search
401,078 resultsCVE-2026-100512CRITICALWordPress Nested Pages plugin <= 3.3.2 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-100510HIGHWordPress Post and Page Builder by BoldGrid plugin <= 1.27.14 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-97291HIGHWordPress Schema & Structured Data for WP & AMP plugin <= 1.66 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-97290HIGHWordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.36 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-97265MEDIUMWordPress JetEngine plugin <= 3.8.15.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-97256HIGHWordPress Page Builder by SiteOrigin plugin <= 2.36.0 - PHP Object Injection vulnerabilityEPSS 0.3%CVE-2026-94171HIGHWordPress CURCY plugin <= 2.2.16 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-102397MEDIUMWordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-103440LOWpagetriagelist discloses suppressed reviewer usernamesEPSS 0.3%CVE-2026-103439LOWVarious rawParams() and escaped() updates to prevent XSS in Wikibase extensionEPSS 0.1%CVE-2026-103438LOWVarious rawParams() and escaped() updates to prevent XSS in Wikistories extensionEPSS 0.1%CVE-2026-55224HIGHMineAdmin: Path Traversal via Unsanitized identifier in Plugin Install/UninstallEPSS 1.2%CVE-2026-55094HIGHTaskcluster: Unauthenticated remote code execution in `web-server` via GraphQL `filter` argument (sift `$where`)EPSS 0.4%CVE-2026-103476MEDIUMyii2-starter-kit through 4.2.0 Unauthorized File Download via attachment-downloadEPSS 0.3%CVE-2026-103475CRITICALyii2-starter-kit through 4.2.0 Debug and Gii Module ExposureEPSS 0.4%CVE-2026-103474HIGHyii2-starter-kit through 4.2.0 Unrestricted File Upload RCEEPSS 0.4%CVE-2026-103473CRITICALDeno 2.7.0 through 2.9.7 Command Injection via node:child_processEPSS 1.5%CVE-2026-103472HIGHrestbed through 5.0.0 WebSocket Memory Exhaustion via Unbounded Frame BufferingEPSS 0.4%CVE-2026-103471HIGHrestbed through 5.0.0 Denial of Service via Unbounded Header BufferingEPSS 0.6%CVE-2026-103437LOWReadingLists imported metadata permits JavaScript URL XSSEPSS 0.3%