CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
228318 CVEs matched. Showing 151–200 (page 4 of 4567).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-95600 |
WordPress TrustedLogin Connector plugin <= 2.0.3 - Sensitive Data Exposure vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95593 |
WordPress Ultimeter plugin <= 3.0.8 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95592 |
WordPress Team plugin <= 6.0.0 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95590 |
WordPress Tainacan plugin <= 1.2.0 - SQL Injection vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95586 |
WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.50 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95530 |
WordPress PixelYourSite – Your smart PIXEL (TAG) Manager plugin <= 11.4.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95529 |
WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95528 |
WordPress Core Web Vitals & PageSpeed Booster plugin <= 1.0.31 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95527 |
WordPress Conekta Payment Gateway plugin <= 6.2.4 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95525 |
WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95524 |
WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95523 |
WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95522 |
WordPress Easy Digital Downloads plugin <= 3.7.0 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95515 |
WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95514 |
WordPress Netgsm plugin <= 2.10.0 - Bypass Vulnerability vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-95513 |
WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.6.0 - Broken Access Control vulnerabil… | HIGH | 7.5 | 7.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94684 |
WordPress Ocean Extra plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94682 |
WordPress Podcast Importer SecondLine plugin <= 1.5.6 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94680 |
WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94679 |
WordPress Fluent Support plugin <= 2.3.2 - Broken Access Control vulnerability | MEDIUM | 5.4 | 5.4 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94671 |
WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94500 |
WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94498 |
WordPress AppMySite plugin <= 3.15.4 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94487 |
WordPress PublishPress Capabilities plugin <= 2.50.1 - Cross Site Request Forgery (CSRF) vulnerability | HIGH | 8.1 | 8.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94461 |
WordPress Ditty plugin <= 3.1.69 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94457 |
WordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerability | MEDIUM | 4.8 | 4.8 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94391 |
WordPress Ultimate FAQ plugin <= 2.4.14 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94179 |
WordPress Razorpay Payment Button plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94176 |
WordPress Mang Board WP plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94174 |
WordPress Email Log plugin <= 2.63 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94168 |
WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94124 |
WordPress WP EasyCart plugin <= 5.9.4 - SQL Injection vulnerability | HIGH | 8.5 | 8.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94118 |
WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94080 |
WordPress MarketKing plugin <= 2.1.70 - Broken Access Control vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-94079 |
WordPress WP User Manager plugin <= 2.9.19 - Broken Access Control vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93774 |
WordPress WP Photo Album Plus plugin <= 9.3.02.002 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93773 |
WordPress Mollie Forms plugin <= 2.11.0 - SQL Injection vulnerability | HIGH | 8.5 | 8.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93772 |
WordPress wpForo Forum plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93623 |
WordPress AI Engine plugin <= 3.7.8 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93622 |
WordPress WPS Limit Login plugin <= 1.5.9.3 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93620 |
WordPress PayPlus Payment Gateway plugin <= 8.2.5 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93618 |
WordPress JetTricks plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93529 |
WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-93527 |
WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability | HIGH | 8.5 | 8.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93526 |
WordPress Event Tickets plugin <= 5.29.4 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93513 |
WordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 4.3 | 4.3 | — | Patchstack | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-77420 |
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable | MEDIUM | 5.5 | 5.5 | — | GitHub_M | 2026-09-23 | — | — | raw · ⬇ |
CVE-2026-77422 |
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75131 |
NetworkManager-l2tp Privilege Escalation via pppd Username Injection | HIGH | 8.5 | 7.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96541 |
Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline | HIGH | 7.5 | 7.5 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |