Export limit exceeded: 369839 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (369839 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15017 2 Mdjm, Wordpress 2 Mdjm Event Management, Wordpress 2026-07-23 8.8 High
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of server-side allow-list validation on the `employee_roles[]` and `new_role` POST parameters before they are passed to `mdjm_set_employee_role()` and `WP_User::set_role()`. This makes it possible for unauthenticated attackers to grant arbitrary MDJM capabilities — including `mdjm_employee` and `mdjm_employee_edit` — to any registered WordPress role, and subsequently leverage a subscriber-level account to escalate privileges to Administrator. `MDJM_Permissions::init()` is registered on the public WordPress `init` hook without any authentication gate, meaning the role-manipulation endpoint is reachable without any prior login.
CVE-2026-15448 2 Tickera, Wordpress 2 Tickera – Sell Tickets & Manage Events, Wordpress 2026-07-23 6.5 Medium
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-65550 2026-07-23 5.9 Medium
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65540 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65539 2026-07-23 7.1 High
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65536 2026-07-23 6.5 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.
CVE-2026-65535 2026-07-23 4.3 Medium
Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.
CVE-2026-65534 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.
CVE-2026-65533 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.
CVE-2026-65532 2026-07-23 7.6 High
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
CVE-2026-65531 2026-07-23 4.8 Medium
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
CVE-2026-65530 2026-07-23 4.3 Medium
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.
CVE-2026-65529 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.
CVE-2026-65528 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
CVE-2026-65527 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.
CVE-2026-65526 2026-07-23 8.5 High
Contributor SQL Injection in Visualizer <= 4.0.6 versions.
CVE-2026-65521 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.
CVE-2026-65519 2026-07-23 6.5 Medium
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.