Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 400567 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (400567 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70650 | 2026-10-01 | N/A | ||
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is saved, but the backup viewer decodes them again (htmldecode() / strip_decode()) and prints the result without re-escaping. A user who can edit a page can store JavaScript in a page's Keywords, Description, Menu text or Content; it executes in the browser of any administrator who later views that page's backup, in the context of the admin control panel. At time of publication, there are no publicly available patches. | ||||
| CVE-2026-56662 | 2026-10-01 | 9.6 Critical | ||
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5. | ||||
| CVE-2026-88408 | 1 Falkordb | 1 Falkordb | 2026-10-01 | 6.5 Medium |
| FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | ||||
| CVE-2026-62084 | 1 Jeff Starr | 1 User Submitted Posts | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810. | ||||
| CVE-2026-53953 | 2026-10-01 | 9.1 Critical | ||
| GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches. | ||||
| CVE-2026-103445 | 1 Wikimedia | 1 Mediawiki-page Forms Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-103437 | 1 Wikimedia | 1 Mediawiki-readinglists Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45. | ||||
| CVE-2026-103438 | 1 Wikimedia | 1 Mediawiki-wikistories Extension | 2026-10-01 | N/A |
| Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43. | ||||
| CVE-2026-102397 | 2 Supsystic, Wordpress-extensions | 2 Ultimate Maps By Supsystic, Ultimate Maps By Supsystic | 2026-10-01 | 6.5 Medium |
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | ||||
| CVE-2026-94171 | 2 Villatheme, Wordpress-extensions | 2 Curcy, Curcy | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in CURCY <= 2.2.16 versions. | ||||
| CVE-2026-97256 | 2 Greg–siteorigin, Wordpress-extensions | 2 Page Builder By Siteorigin, Page Builder By Siteorigin | 2026-10-01 | 7.2 High |
| Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions. | ||||
| CVE-2026-97265 | 2 Crocoblock. Jetimpex Inc., Wordpress-extensions | 2 Jetengine, Jetengine | 2026-10-01 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | ||||
| CVE-2026-97290 | 2 Sayontan Sinha, Wordpress-extensions | 2 Photonic Gallery & Lightbox For Flickr, Smugmug & Others, Photonic Gallery & Lightbox For Flickr, Smugmug & Others | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions. | ||||
| CVE-2026-97291 | 2 Magazine3, Wordpress-extensions | 2 Schema & Structured Data For Wp & Amp, Schema & Structured Data For Wp & Amp | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | ||||
| CVE-2026-100510 | 2 Boldgrid, Wordpress-extensions | 2 Post And Page Builder, Post And Page Builder By Boldgrid | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions. | ||||
| CVE-2026-100512 | 2 Hook & Filter, Wordpress-extensions | 2 Nested Pages, Nested Pages | 2026-10-01 | 9.8 Critical |
| Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | ||||
| CVE-2026-102375 | 2 Optimole, Wordpress-extensions | 2 Optimole, Optimole | 2026-10-01 | 6.5 Medium |
| Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | ||||
| CVE-2026-102376 | 2 Wordpress-extensions, Wpmudev | 2 Branda, Branda | 2026-10-01 | 7.1 High |
| Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions. | ||||
| CVE-2026-102377 | 2 10web, Wordpress-extensions | 2 Photo Gallery, Photo Gallery By 10web | 2026-10-01 | 8.8 High |
| Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions. | ||||
| CVE-2026-102391 | 2 Jetmonsters, Wordpress-extensions | 2 Jetformbuilder, Jetformbuilder | 2026-10-01 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | ||||