Search

Search Results (402505 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103355 2 Unlimited-elements, Wordpress-extensions 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Unlimited Elements For Elementor 2026-10-06 9.3 Critical
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
CVE-2026-103349 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.5.7.
CVE-2026-103348 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.
CVE-2026-103346 2026-10-06 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1.
CVE-2026-103337 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Kirillbdev WC Ukraine Shipping wc-ukr-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WC Ukraine Shipping: from n/a through 1.23.2.
CVE-2026-103086 2026-10-06 6.5 Medium
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.
CVE-2026-103066 2026-10-06 8.5 High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
CVE-2026-102915 2026-10-06 8.5 High
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
CVE-2026-102387 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions.
CVE-2026-100518 2026-10-06 5.3 Medium
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
CVE-2026-100515 2026-10-06 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30.
CVE-2026-100511 2026-10-06 8.8 High
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
CVE-2026-100506 2026-10-06 7.2 High
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
CVE-2025-15643 2026-10-06 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4.
CVE-2026-59668 1 Repasat 1 Repasat Application 2026-10-06 N/A
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizebills/store”.
CVE-2026-59667 1 Repasat 1 Repasat Application 2026-10-06 N/A
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomTamano” parameter is affected – endpoint “/es/companysizemployees/update”.
CVE-2026-59666 1 Repasat 1 Repasat Application 2026-10-06 N/A
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomOrigen” parameter is affected – endpoint “/es/origins/store”.
CVE-2026-59665 1 Repasat 1 Repasat Application 2026-10-06 N/A
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomMotivo” parameter is affected – endpoint “/es/lostmotives/store”.
CVE-2026-59664 1 Repasat 1 Repasat Application 2026-10-06 N/A
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomServicioPrestado” parameter is affected – endpoint “/es/providedservices/store”.
CVE-2026-59663 1 Repasat 1 Repasat Application 2026-10-06 N/A
Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s browser. The “nomDelegacion” parameter is affected – endpoint “/es/delegations/store”.