7.2

CVSS3.1

CVE-2026-5694 - Quick Interest Slider <= 3.1.5 - Unauthenticated Stored Cross-Site Scripting

The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'loan-period' parameters in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

📅 Published: April 15, 2026, 7:45 a.m. 🔄 Last Modified: April 15, 2026, 3:51 p.m.

8.8

CVSS3.1

CVE-2026-5617 - Login as User <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admi…

The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() function trusting a client-controlled cookie (oclaup_original_admin) to determine which user to authenticate as, without any server-s…

📅 Published: April 15, 2026, 7:45 a.m. 🔄 Last Modified: April 15, 2026, 4:13 p.m.

6.4

CVSS3.1

CVE-2026-5717 - VI: Include Post By <= 0.4.200706 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'c…

The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in all versions up to, and including, 0.4.200706 due to insufficient input sanitization and output escaping on user supplied attribute…

📅 Published: April 15, 2026, 7:45 a.m. 🔄 Last Modified: April 15, 2026, 2:53 p.m.

7.5

CVSS3.1

CVE-2026-5088 - Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts

Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and _make_salt_bcrypt methods will attept to load Crypt::URandom and then Bytes::Random::Secure to generate random bytes for the salt. If those modules are unavailable, it will simp…

📅 Published: April 15, 2026, 7:03 a.m. 🔄 Last Modified: May 6, 2026, 2:18 p.m.

4.3

CVSS3.1

CVE-2026-6293 - Inquiry form to posts or pages <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting v…

The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplie…

📅 Published: April 15, 2026, 6:46 a.m. 🔄 Last Modified: April 16, 2026, 1:38 p.m.

7.5

CVSS3.1

CVE-2026-40719 - Deadwood Exploit Causing Connection Slot Exhaustion in MaraDNS

Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.

📅 Published: April 15, 2026, 6:23 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

5.1

CVSS4.0

CVE-2026-5160 - github.com/yuin/goldmark/renderer/html: github.com/yuin/goldmark/renderer/html: Cross-site Scriptin…

Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities…

📅 Published: April 15, 2026, 5 a.m. 🔄 Last Modified: April 23, 2026, 5 p.m.

4.8

CVSS4.0

CVE-2026-26291 -

Stored cross-site scripting vulnerability exists in GROWI v7.4.6 and earlier. If this vulnerability is exploited, an arbitrary script may be executed in a user's web browser.

📅 Published: April 15, 2026, 4:19 a.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.8

CVSS3.1

CVE-2026-5397 - Vulnerability Related to an Uncontrolled Search Path Element in a UPS Management Application

It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management application, whereby improper permissions on the installation directory allow a malicious actor to place a DLL that is then executed with administrator privileges. If a malicious DLL i…

📅 Published: April 15, 2026, 4:11 a.m. 🔄 Last Modified: April 17, 2026, 3:17 p.m.

9.8

CVSS3.1

CVE-2026-1555 - WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload

The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_img_upload() function in all versions up to, and including, 1.2024. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server whi…

📅 Published: April 15, 2026, 3:37 a.m. 🔄 Last Modified: April 22, 2026, 8:23 p.m.
Total resulsts: 349182
Page 448 of 34,919
« previous page » next page
Filters