CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 182 of 183
CVE-2026-16482
HIGH

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and includ...

CVSS 7.5 2026-09-12
CVE-2026-11355
MEDIUM

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including...

CVSS 5.3 2026-09-12
CVE-2026-87918
MEDIUM

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unaut...

CVSS 5.3 2026-09-12
CVE-2026-87916
MEDIUM

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to re...

CVSS 5.3 2026-09-12
CVE-2026-87894
MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking ...

CVSS 5.3 2026-09-12
CVE-2026-87892
MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a bookin...

CVSS 5.3 2026-09-12
CVE-2026-87891
MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attacke...

CVSS 6.5 2026-09-12
CVE-2026-87888
HIGH

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and abov...

CVSS 8 2026-09-12
CVE-2026-87842
HIGH

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated a...

CVSS 7.5 2026-09-12
CVE-2026-87759
HIGH

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied...

CVSS 8.8 2026-09-12
CVE-2026-86790
MEDIUM

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow user...

CVSS 6.8 2026-09-12
CVE-2026-85681
CRITICAL

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both th...

CVSS 9.8 2026-09-12
CVE-2026-84171
CRITICAL

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing u...

CVSS 9.8 2026-09-12
CVE-2026-84099
HIGH

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the per...

CVSS 8.1 2026-09-12
CVE-2026-84047
HIGH

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQ...

CVSS 8.6 2026-09-12
CVE-2026-84023
MEDIUM

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tr...

CVSS 6.5 2026-09-12
CVE-2026-83532
MEDIUM

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contribu...

CVSS 6.8 2026-09-12
CVE-2026-82847
MEDIUM

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instr...

CVSS 6.8 2026-09-12
CVE-2026-82845
CRITICAL

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minim...

CVSS 9.9 2026-09-12
CVE-2026-81742
HIGH

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitiz...

CVSS 8.8 2026-09-12
1 180 181 182 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.