4.3

CVSS3.1

CVE-2026-28080 - WordPress Rank Math SEO PRO plugin <= 3.0.95 - Broken Access Control vulnerability

Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rank Math SEO PRO: from n/a through 3.0.95.

πŸ“… Published: March 6, 2026, 12:04 p.m. πŸ”„ Last Modified: March 6, 2026, 12:04 p.m.

4.7

CVSS3.1

CVE-2026-28106 - WordPress B2BKing Premium plugin <= 5.3.80 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This issue affects B2BKing Premium: from n/a through 5.3.80.

πŸ“… Published: March 6, 2026, 11:49 a.m. πŸ”„ Last Modified: March 6, 2026, 11:49 a.m.

5.9

CVSS3.1

CVE-2024-35644 - WordPress Preferred Languages plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birchler Preferred Languages allows DOM-Based XSS.This issue affects Preferred Languages: from n/a through 2.2.2.

πŸ“… Published: March 6, 2026, 11:40 a.m. πŸ”„ Last Modified: March 6, 2026, 11:40 a.m.

5.1

CVSS4.0

CVE-2026-1468 - Cross-Site Request Forgery in QuickCMS

QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the victim, will automatically send a POST request with victim's privileges. This software does not implement any protection against this type of attack. All …

πŸ“… Published: March 6, 2026, 11:04 a.m. πŸ”„ Last Modified: March 6, 2026, 11:04 a.m.

0.0

CVE-2026-3589 - WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

πŸ“… Published: March 6, 2026, 9:11 a.m. πŸ”„ Last Modified: March 6, 2026, 9:11 a.m.

5.1

CVSS4.0

CVE-2026-23925 - Unauthorized host creation via configuration.import API by low-privilege user with write permissions

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even …

πŸ“… Published: March 6, 2026, 8:24 a.m. πŸ”„ Last Modified: March 6, 2026, 8:24 a.m.

9.8

CVSS3.1

CVE-2026-2331 - CVE-2026-2331

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without…

πŸ“… Published: March 6, 2026, 7:56 a.m. πŸ”„ Last Modified: March 6, 2026, 7:56 a.m.

9.4

CVSS3.1

CVE-2026-2330 - CVE-2026-2330

An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelist enforcement. Certain directories intended for internal testing were not covered by the whitelist and are accessible without authentication. An unauthenticated attacker could pla…

πŸ“… Published: March 6, 2026, 7:54 a.m. πŸ”„ Last Modified: March 6, 2026, 7:54 a.m.

7.5

CVSS3.1

CVE-2026-29074 - SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion…

πŸ“… Published: March 6, 2026, 7:23 a.m. πŸ”„ Last Modified: March 6, 2026, 7:23 a.m.

6.1

CVSS3.1

CVE-2026-2830 - WP All Import <= 4.0.0 - Reflected Cross-Site Scripting via 'filepath'

The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜filepath’ parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible…

πŸ“… Published: March 6, 2026, 7:22 a.m. πŸ”„ Last Modified: March 6, 2026, 7:22 a.m.
Total resulsts: 336512
Page 16 of 33,652
Β« previous page Β» next page
Filters