Vulnerabilities in Unknown

5,639 results
CVE-2026-11866MEDIUMLatePoint < 5.6.3 - Multiple Privileged Actions via CSRFEPSS 0.1%CVE-2025-12696MEDIUMHelloLeads CRM Form Shortcode <= 1.0 - Unauthenticated Settings ResetEPSS 0.1%CVE-2026-91017LOWRobokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT CallbackEPSS 0.1%CVE-2026-103323MEDIUMIntegration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue DisclosureEPSS 0.1%CVE-2026-18044LOWEstatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value MismatchEPSS 0.1%CVE-2026-96524HIGHMCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRFEPSS 0.1%CVE-2026-87069LOWForminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripeEPSS 0.1%CVE-2026-91023LOWMotors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featuredEPSS 0.1%CVE-2026-104049MEDIUMAcademy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST EndpointEPSS 0.1%CVE-2026-16292MEDIUMFrontend File Manager Plugin <= 23.6 - File Metadata Update via CSRFEPSS 0.1%CVE-2026-103681MEDIUMFrontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_deleteEPSS 0.1%CVE-2026-93507LOWWC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content DisclosureEPSS 0.1%CVE-2026-104651MEDIUMYaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulation via IDOREPSS 0.1%CVE-2026-104050MEDIUMAcademy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answersEPSS 0.1%CVE-2026-82212HIGHNexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification HandlerEPSS 0.1%CVE-2026-81429HIGHExport & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRFEPSS 0.1%CVE-2026-101147HIGHFeatured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRFEPSS 0.1%CVE-2026-1508MEDIUMCourt Reservation < 1.10.9 - Event Deletion via CSRFEPSS 0.1%CVE-2026-14565MEDIUMAdvanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup ConfigurationEPSS 0.1%CVE-2026-10724MEDIUMReviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google ReviewsEPSS 0.1%