5.1

CVSS4.0

CVE-2026-5838 - PHPGurukul News Portal Project add-subadmins.php sql injection

A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed anโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:30 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

6.4

CVSS3.1

CVE-2026-5742 - UsersWP <= 1.2.60 - Authenticated (Subscriber+) Stored Cross-Site Scripting via User Badge Link Subโ€ฆ

The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible forโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

6.4

CVSS3.1

CVE-2026-4336 - Ultimate FAQ Accordion Plugin <= 2.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via FAโ€ฆ

The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.pโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

9.8

CVSS3.1

CVE-2026-1830 - Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated aโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

6.9

CVSS4.0

CVE-2026-5837 - PHPGurukul News Portal Project news-details.php sql injection

A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

๐Ÿ“… Published: April 9, 2026, 3:15 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

4.8

CVSS4.0

CVE-2026-5836 - code-projects Online Shoe Store admin_product.php cross site scripting

A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument product_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been dโ€ฆ

๐Ÿ“… Published: April 9, 2026, 3 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

4.8

CVSS4.0

CVE-2026-5835 - code-projects Online Shoe Store admin_football.php cross site scripting

A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argument product_name can lead to cross site scripting. It is possible to launch the attack remotely. The eโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:45 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

4.8

CVSS4.0

CVE-2026-5834 - code-projects Online Shoe Store admin_running.php cross site scripting

A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now publiโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:30 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:03 p.m.

4.3

CVSS3.1

CVE-2026-3568 - MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Usโ€ฆ

The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:04 p.m.

4.4

CVSS3.1

CVE-2026-3574 - Experto Dashboard for WooCommerce <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripโ€ฆ

The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight') in all versionsโ€ฆ

๐Ÿ“… Published: April 9, 2026, 2:25 a.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:04 p.m.
Total resulsts: 349182
Page 571 of 34,919
ยซ previous page ยป next page
Filters