Vulnerabilities in Unknown

5,639 results
CVE-2026-80342MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.27 - Unauthenticated Payment Hijacking via Unvalidated PayPal Order IDEPSS 0.2%CVE-2026-12865HIGHPhoto Gallery by 10Web < 1.8.44 - Reflected XSS via title and paged ParametersEPSS 0.2%CVE-2025-8280MEDIUMContact Form 7 reCAPTCHA <= 1.2.0 - Reflected XSS via $_SERVER['REQUEST_URI']EPSS 0.2%CVE-2024-3076LOWMM-email2image <= 0.2.5 - Stored XSS via CSRFEPSS 0.2%CVE-2024-8091MEDIUMEnhanced Search Box <= 0.6.1 - Settings Update via CSRFEPSS 0.2%CVE-2026-78371MEDIUMFile Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File DisclosureEPSS 0.2%CVE-2026-87848LOWMPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content DisclosureEPSS 0.2%CVE-2024-7862MEDIUMBlog Introduction <= 0.3.0 - Settings Update via CSRFEPSS 0.2%CVE-2024-7690MEDIUMDN Popup <= 1.2.2 - Settings Update via CSRFEPSS 0.2%CVE-2024-7820MEDIUMILC Thickbox <= 1.0 - Settings update via CSRFEPSS 0.2%CVE-2024-3971MEDIUMSimilarity <= 3.0 - Plugin Reset via CSRFEPSS 0.2%CVE-2026-100143MEDIUMFluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout EmailEPSS 0.2%CVE-2025-9115MEDIUMEtsy Shop < 3.0.7 - Reflected XSS via $_SERVER['REQUEST_URI']EPSS 0.2%CVE-2026-12586HIGHLenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password ResetEPSS 0.2%CVE-2026-90974MEDIUMWP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings UpdateEPSS 0.2%CVE-2024-4534MEDIUMKKProgressbar2 Free <= 1.1.4.2 - Stored XSS via CSRFEPSS 0.2%CVE-2024-0756LOWInsert or Embed Articulate Content into WordPress <= 4.3000000023 - Iframe InjectionEPSS 0.2%CVE-2024-7689MEDIUMSnapshot Backup <= 2.1.1 - Stored XSS via CSRFEPSS 0.2%CVE-2023-7196MEDIUMUltimate Noindex Nofollow Tool <= 1.1.2 - Settings Update via CSRFEPSS 0.2%CVE-2024-10480MEDIUM3DPrint Lite < 2.1 - Settings Update via CSRFEPSS 0.2%