4.3

CVSS3.1

CVE-2026-4002 - Petje.af <= 2.1.8 - Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Ac…

The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8. This is due to missing nonce validation in the ajax_revoke_token() function which handles the 'petjeaf_disconnect' AJAX action. The function performs destructive operations inclu…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

6.4

CVSS3.1

CVE-2026-3659 - WP Circliful <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode A…

The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [circliful] shortcode and via multiple shortcode attributes of the [circliful_direct] shortcode in all versions up to and including 1.2. This is due to insufficient input sanit…

📅 Published: April 15, 2026, 8:28 a.m. 🔄 Last Modified: April 15, 2026, 8:28 a.m.

7.1

CVSS4.0

CVE-2025-40899 - Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Asset…

📅 Published: April 15, 2026, 8:18 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.2

CVSS4.0

CVE-2025-40897 - Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Threat Intelligence functionality can perform adminis…

📅 Published: April 15, 2026, 8:18 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.2

CVSS3.1

CVE-2026-5694 - Quick Interest Slider <= 3.1.5 - Unauthenticated Stored Cross-Site Scripting

The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'loan-period' parameters in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

📅 Published: April 15, 2026, 7:45 a.m. 🔄 Last Modified: April 15, 2026, 7:45 a.m.

8.8

CVSS3.1

CVE-2026-5617 - Login as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admi…

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-s…

📅 Published: April 15, 2026, 7:45 a.m. 🔄 Last Modified: April 15, 2026, 7:45 a.m.

6.4

CVSS3.1

CVE-2026-5717 - VI: Include Post By <= 0.4.200706 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'c…

The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in all versions up to, and including, 0.4.200706 due to insufficient input sanitization and output escaping on user supplied attribute…

📅 Published: April 15, 2026, 7:45 a.m. 🔄 Last Modified: April 15, 2026, 7:45 a.m.

7.5

CVSS3.1

CVE-2026-5088 - Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts

Apache::API::Password versions through v0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will sim…

📅 Published: April 15, 2026, 7:03 a.m. 🔄 Last Modified: April 17, 2026, 9 a.m.

4.3

CVSS3.1

CVE-2026-6293 - Inquiry form to posts or pages <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting v…

The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplie…

📅 Published: April 15, 2026, 6:46 a.m. 🔄 Last Modified: April 16, 2026, 1:38 p.m.

7.5

CVSS3.1

CVE-2026-40719 - Deadwood Exploit Causing Connection Slot Exhaustion in MaraDNS

Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.

📅 Published: April 15, 2026, 6:23 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 345133
Page 48 of 34,514
« previous page » next page
Filters