3.8

CVSS3.1

CVE-2025-67860 - NeuVector scanner insecurely handles passwords as command arguments

A vulnerability has been identified in the NeuVector scanner where the scanner process accepts registry and controller credentials as command-line arguments, potentially exposing sensitive credentials to local users.

📅 Published: Feb. 25, 2026, 10:33 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-2367 - Secure Copy Content Protection and Content Locking <= 5.0.1 - Authenticated (Contributor+) Stored C…

The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ays_block' shortcode in all versions up to, and including, 5.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This ma…

📅 Published: Feb. 25, 2026, 9:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2026-2301 - Post Duplicator <= 3.0.8 - Missing Authorization to Authenticated (Contributor+) Protected Post Met…

The Post Duplicator plugin for WordPress is vulnerable to unauthorized arbitrary protected post meta insertion in all versions up to, and including, 3.0.8. This is due to the `duplicate_post()` function in `includes/api.php` using `$wpdb->insert()` directly to the `wp_postmeta` table instead of Wor…

📅 Published: Feb. 25, 2026, 9:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2026-2410 - Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugi…

The Disable Admin Notices – Hide Dashboard Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing nonce validation in the `showPageContent()` function. This makes it possible for unauthenticated attackers to…

📅 Published: Feb. 25, 2026, 9:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-14742 - WP Recipe Maker <= 10.2.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Informat…

The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up to, and including, 10.2.3. This makes it possible for authenticated attackers, with Subscriber-leve…

📅 Published: Feb. 25, 2026, 9:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2026-3171 - SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System queue.php cross site scr…

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /queue.php. This manipulation of the argument firstname/lastname causes cross site scripting. The attack is possible to be …

📅 Published: Feb. 25, 2026, 8:32 a.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

8.8

CVSS3.1

CVE-2026-1929 - Advanced Woo Labels <= 2.37 - Authenticated (Contributor+) Remote Code Execution via 'callback' Par…

The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.37. This is due to the use of `call_user_func_array()` with user-controlled callback and parameters in the `get_select_option_values()` AJAX handler without an allowlist of pe…

📅 Published: Feb. 25, 2026, 8:25 a.m. 🔄 Last Modified: April 16, 2026, midnight

7.5

CVSS3.1

CVE-2026-2416 - Geo Mashup <= 1.13.17 - Unauthenticated SQL Injection via 'sort' Parameter

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for una…

📅 Published: Feb. 25, 2026, 8:25 a.m. 🔄 Last Modified: April 21, 2026, 11:45 p.m.

7.5

CVSS3.1

CVE-2026-1916 - WPGSI: Spreadsheet Integration <= 3.8.3 - Missing Authorization to Unauthenticated Arbitrary Post C…

The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due to missing capability checks and an insecure authentication mechanism on the `wpgsi_callBackFuncAccept` and `wpgsi_callBackFuncUpdate` REST API functions in all versions up to, an…

📅 Published: Feb. 25, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2026-2479 - Responsive Lightbox & Gallery <= 2.7.1 - Authenticated (Author+) Server-Side Request Forgery via Re…

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.1. This is due to the use of `strpos()` for substring-based hostname validation instead of strict host comparison in the `ajax_upload_image()` function. This…

📅 Published: Feb. 25, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346514
Page 1181 of 34,652
« previous page » next page
Filters