8.6

CVSS4.0

CVE-2026-22550 - OS Command Injection in Elecom WRC Router Models

OS command injection vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. A crafted request from a logged-in user may lead to an arbitrary OS command execution.

📅 Published: Feb. 3, 2026, 6:56 a.m. 🔄 Last Modified: April 18, 2026, 2:30 p.m.

5.1

CVSS4.0

CVE-2026-20704 - Cross‑Site Request Forgery Enabling Unintended Operations on WRC‑X1500GS‑B and WRC‑X1500GSA‑B

Cross-site request forgery vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.

📅 Published: Feb. 3, 2026, 6:56 a.m. 🔄 Last Modified: April 18, 2026, 12:30 a.m.

5.4

CVSS3.1

CVE-2026-1447 - Mail Mint <= 1.19.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19.2. This is due to missing nonce validation on the create_or_update_note function. This makes it possible for unauthenticated attackers to create or update contact notes via a fo…

📅 Published: Feb. 3, 2026, 6:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2026-1058 - Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field

The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses html_entity_decode()…

📅 Published: Feb. 3, 2026, 6:38 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

6.4

CVSS3.1

CVE-2026-1210 - Happy Addons for Elementor <= 3.20.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_data' meta field in all versions up to, and including, 3.20.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con…

📅 Published: Feb. 3, 2026, 6:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-1065 - Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This makes it possible for …

📅 Published: Feb. 3, 2026, 6:38 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2026-0617 - LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored C…

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This makes it possible for un…

📅 Published: Feb. 3, 2026, 6:38 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

4.6

CVSS4.0

CVE-2025-58381 - Directory transversal vulnerability in Brocade Fabric OS before 9.2.1c2 and 9.2.2 through 9.2.2a us…

A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different directories.

📅 Published: Feb. 3, 2026, 5:40 a.m. 🔄 Last Modified: Feb. 6, 2026, 8:53 p.m.

5.3

CVSS3.1

CVE-2026-0950 - Spectra Gutenberg Blocks <= 2.19.17 - Unauthenticated Information Disclosure in Sensitive Data

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt…

📅 Published: Feb. 3, 2026, 5:30 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-14274 - Unlimited Elements for Elementor <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authent…

📅 Published: Feb. 3, 2026, 5:30 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347696
Page 1694 of 34,770
« previous page » next page
Filters