CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 24 of 500
CVE-2026-84906
MEDIUM

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the ...

CVSS 5.3 2026-09-16
CVE-2026-13407
MEDIUM

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of admi...

CVSS 5.4 2026-09-16
CVE-2024-11222
MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have a...

CVSS 6.4 2026-09-16
CVE-2026-88910
MEDIUM

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media...

CVSS 5.3 2026-09-16
CVE-2026-87959
MEDIUM

The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users with subscriber-level acc...

CVSS 5.4 2026-09-16
CVE-2026-87907
MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unau...

CVSS 5.3 2026-09-16
CVE-2026-87896
MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthentic...

CVSS 5.3 2026-09-16
CVE-2026-87854
MEDIUM

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users t...

CVSS 5.3 2026-09-16
CVE-2026-87828
MEDIUM

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as subscr...

CVSS 5.7 2026-09-16
CVE-2026-86823
MEDIUM

The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to ...

CVSS 5.3 2026-09-16
CVE-2026-92358
MEDIUM

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the ...

CVSS 6.4 2026-09-16
CVE-2026-86784
MEDIUM

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, allowing users wi...

CVSS 6.8 2026-09-16
CVE-2026-86449
MEDIUM

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST routes, allowing unauthen...

CVSS 5.3 2026-09-16
CVE-2026-86447
MEDIUM

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every enr...

CVSS 5.3 2026-09-16
CVE-2026-86445
MEDIUM

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve ...

CVSS 5.3 2026-09-16
CVE-2026-85131
MEDIUM

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does not restrict ...

CVSS 6.5 2026-09-16
CVE-2026-84088
MEDIUM

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using it in a JavaScript navigatio...

CVSS 6.8 2026-09-16
CVE-2026-82125
MEDIUM

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, a...

CVSS 5.3 2026-09-16
CVE-2026-82124
MEDIUM

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its content in the structured data it ge...

CVSS 5.3 2026-09-16
CVE-2026-78474
MEDIUM

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthentic...

CVSS 5.3 2026-09-16
1 22 23 24 25 26 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.