5.3

CVSS3.1

CVE-2026-3567 - RepairBuddy <= 4.1132 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modifi…

The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 4.1132. The plugin exposes two AJAX handlers that, when combined, allow any authenticated user to modify admin-level plugin settings. First, the wc_rb_get_fres…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-3516 - Contact List <= 3.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_cl_map_ifra…

The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in all versions up to, and including, 3.0.18. This is due to insufficient input sanitization and output escaping when handling the Google Maps iframe custom field. The saveCustomFie…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-2352 - Autoptimize <= 3.1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ao_post_prelo…

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value in all versions up to, and including, 3.1.14. This is due to insufficient input sanitization in the `ao_metabox_save()` function and missing output escaping when the value is rende…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.1

CVSS3.1

CVE-2026-3572 - iTracker360 <= 2.2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_lice…

The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in all versions up to and including 2.2.0. This is due to missing nonce verification on the settings form submission and insufficient input sanitization combined with missing outp…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

6.4

CVSS3.1

CVE-2026-4083 - Scoreboard for HTML5 Games Lite <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.4

CVSS3.1

CVE-2026-3577 - Keep Backup Daily <= 2.1.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Backup Title

The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val` parameter) in the `update_kbd_bkup_alias` AJAX action in all versions up to, and including, 2.1.2. This is due to insufficient input sanitization and output escaping. While `san…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

7.2

CVSS3.1

CVE-2026-3368 - Injection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Parameter Name

The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter names in all versions up to and including 1.2.9. This is due to insufficient input sanitization in the sanitize_ig_data() function which only sanitizes array values but not array keys…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

2.7

CVSS3.1

CVE-2026-3339 - Keep Backup Daily <= 2.1.1 - Authenticated (Admin+) Limited Path Traversal via 'kbd_path' Parameter

The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including, 2.1.1 via the `kbd_open_upload_dir` AJAX action. This is due to insufficient validation of the `kbd_path` parameter, which is only sanitized with `sanitize_text_field()` - a func…

📅 Published: March 20, 2026, 11:25 p.m. 🔄 Last Modified: April 22, 2026, 9:32 p.m.

4.9

CVSS4.0

CVE-2026-33428 - Discourse Allows Unauthorized Access to Deleted Posts Index via Group Membership

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staff user with elevated group membership could access deleted posts belonging to any user due to an overly broad authorization check on the deleted posts index endpoint. Versions 202…

📅 Published: March 20, 2026, 11:21 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.

2.7

CVSS4.0

CVE-2026-33427 - Discourse Authorization Page Displays Unvalidated Redirect Domain

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthenticated attacker can cause a legitimate Discourse authorization page to display an attacker-controlled domain, facilitating social engineering attacks against users. Versions 202…

📅 Published: March 20, 2026, 11:20 p.m. 🔄 Last Modified: March 25, 2026, 2:33 p.m.
Total resulsts: 349182
Page 1005 of 34,919
« previous page » next page
Filters