5.3

CVSS3.1

CVE-2026-1650 - MDJM Event Management <= 1.7.8.1 - Missing Authorization to Unauthenticated Arbitrary Custom Event …

The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'custom_fields_controller' function in all versions up to, and including, 1.7.8.1. This makes it possible for unauthenticated attackers to delete arbitrary custom …

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

4.9

CVSS3.1

CVE-2026-2429 - Community Events <= 1.5.8 - Authenticated (Administrator+) SQL Injection via 'ce_venue_name' CSV Fi…

The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_save_changes_venues` function in all versions up to, and including, 1.5.8. This is due to insufficient escaping on the user-supplied CSV data and lack of sufficient preparation on t…

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-2020 - JS Archive List <= 6.1.7 - Authenticated (Contributor+) PHP Object Injection via 'included' Shortco…

The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1.7 via the 'included' shortcode attribute. This is due to the deserialization of untrusted input supplied via the 'included' parameter of the plugin's shortcode. This makes it pos…

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2025-14353 - ZIP Code Based Content Protection <= 1.0.2 - Unauthenticated SQL Injection via 'zipcode' Parameter

The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m…

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

4.3

CVSS3.1

CVE-2026-2494 - ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it poss…

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

4.3

CVSS3.1

CVE-2026-2488 - ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Del…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting …

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

6.4

CVSS3.1

CVE-2026-1902 - Hammas Calendar <= 1.5.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'apix' Sho…

The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'hp-calendar-manage-redirect' shortcode in all versions up to, and including, 1.5.11 due to insufficient input sanitization and output escaping. This makes it possible for authentic…

📅 Published: March 7, 2026, 1:21 a.m. 🔄 Last Modified: April 22, 2026, 9:27 p.m.

5.1

CVSS4.0

CVE-2026-25073 - XikeStor SKS8310-8X Stored XSS via System Name

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary script content through the System Name field. Attackers can inject malicious scripts that execute in a victim's browser…

📅 Published: March 7, 2026, 12:20 a.m. 🔄 Last Modified: April 16, 2026, 11:15 a.m.

8.6

CVSS4.0

CVE-2026-25072 - XikeStor SKS8310-8X Predictable Session Identifiers

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnerability in the /goform/SetLogin endpoint that allows remote attackers to hijack authenticated sessions. Attackers can predict session identifiers using insufficiently random cookie…

📅 Published: March 7, 2026, 12:20 a.m. 🔄 Last Modified: April 16, 2026, 11:15 a.m.

8.7

CVSS4.0

CVE-2026-25071 - XikeStor SKS8310-8X switch_config.src Missing Authentication

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability in the /switch_config.src endpoint that allows unauthenticated remote attackers to download device configuration files. Attackers can access this endpoint without credentials to re…

📅 Published: March 7, 2026, 12:20 a.m. 🔄 Last Modified: April 16, 2026, 11:15 a.m.
Total resulsts: 346618
Page 1012 of 34,662
« previous page » next page
Filters