6.4

CVSS3.1

CVE-2026-4088 - Switch CTA Box <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user-supplied post meta values including 'cta_box_button_link', 'cta…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 23, 2026, 1:42 p.m.

5.5

CVSS3.1

CVE-2026-1845 - Real Estate Pro <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting via Settings

The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions a…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

4.4

CVSS3.1

CVE-2026-6041 - Buzz Comments <= 0.9.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Buz…

The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_comments_avatar_image) setting in all versions up to, and including, 0.9.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authentic…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 6:23 p.m.

6.1

CVSS3.1

CVE-2026-4131 - WP Responsive Popup + Optin <= 1.4 - Cross-Site Request Forgery to Stored Cross-Site Scripting via …

The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_r…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

6.4

CVSS3.1

CVE-2026-4082 - ER Swiffy Insert <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode …

The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all versions up to and including 1.0.0. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes ('n', 'w', 'h'). These attributes are…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

6.4

CVSS3.1

CVE-2026-4279 - Bread & Butter: Content Gating for Verified Leads <= 8.2.0.25 - Authenticated (Contributor+) Stored…

The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versions up to, and including, 8.2.0.25. This is due to insufficient input sanitization and output escaping on the 'event' shortcode attribute. The customEv…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 6:22 p.m.

4.4

CVSS3.1

CVE-2026-1379 - HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Hea…

The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 8:22 p.m.

6.4

CVSS3.1

CVE-2026-5820 - Zypento Blocks <= 1.0.6 - Authenticated (Author+) Stored Cross-Site Scripting via Table of Contents…

The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 1.0.6. This is due to the front-end TOC rendering script reading heading text via `innerText` and inserting it into the page using `innerHTML` w…

📅 Published: April 22, 2026, 7:45 a.m. 🔄 Last Modified: April 22, 2026, 1:06 p.m.

8.1

CVSS3.1

CVE-2026-6023 - Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.

📅 Published: April 22, 2026, 7:13 a.m. 🔄 Last Modified: April 23, 2026, 3:56 a.m.

7.5

CVSS3.1

CVE-2026-6022 - Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.

📅 Published: April 22, 2026, 7:07 a.m. 🔄 Last Modified: April 22, 2026, 12:28 p.m.
Total resulsts: 346531
Page 67 of 34,654
« previous page » next page
Filters