Export limit exceeded: 369839 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369839 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-15017 | 2 Mdjm, Wordpress | 2 Mdjm Event Management, Wordpress | 2026-07-23 | 8.8 High |
| The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login. | ||||
| CVE-2026-15448 | 2 Tickera, Wordpress | 2 Tickera – Sell Tickets & Manage Events, Wordpress | 2026-07-23 | 6.5 Medium |
| The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-65550 | 2026-07-23 | 5.9 Medium | ||
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | ||||
| CVE-2026-65540 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. | ||||
| CVE-2026-65539 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | ||||
| CVE-2026-65538 | 2026-07-23 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | ||||
| CVE-2026-65537 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | ||||
| CVE-2026-65536 | 2026-07-23 | 6.5 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions. | ||||
| CVE-2026-65535 | 2026-07-23 | 4.3 Medium | ||
| Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | ||||
| CVE-2026-65534 | 2026-07-23 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | ||||
| CVE-2026-65533 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | ||||
| CVE-2026-65532 | 2026-07-23 | 7.6 High | ||
| Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | ||||
| CVE-2026-65531 | 2026-07-23 | 4.8 Medium | ||
| Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions. | ||||
| CVE-2026-65530 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | ||||
| CVE-2026-65529 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions. | ||||
| CVE-2026-65528 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | ||||
| CVE-2026-65527 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | ||||
| CVE-2026-65526 | 2026-07-23 | 8.5 High | ||
| Contributor SQL Injection in Visualizer <= 4.0.6 versions. | ||||
| CVE-2026-65521 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions. | ||||
| CVE-2026-65519 | 2026-07-23 | 6.5 Medium | ||
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||||