CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 40451 CVEs

CVE ID Severity Description EPSS Published
8.5 HIGH

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

0.3% 2026-06-16
7.5 HIGH

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

0.3% 2026-06-16
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

0.1% 2026-06-16
7.5 HIGH

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

0.2% 2026-06-16
8.8 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up to, and including, 12.6.8. This is due to the handler reading $_POST['curselrevs'] raw with no sanitization or type casting, then concatenating each array element directly into a `WHERE id IN ( ... )` clause without quoting and executing via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.3% 2026-06-16
8.8 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in versions up to, and including, 12.6.8. This is due to the use of stripslashes() on user-supplied JSON strings prior to json_decode(), which removes the escaping applied by WordPress's wp_magic_quotes; the resulting decoded array values are then concatenated directly into SQL WHERE clauses without parameterization, and the constructed query is executed via $wpdb->get_results() without $wpdb->prepare(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The handler also returns the executed SQL string in its JSON response, which simplifies oracle construction for blind exploitation.

0.3% 2026-06-16
8.8 HIGH

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is due to the 'generatePluginHandler' function lacking any authorization check before processing user-supplied POST data, combined with the 'createFromStub' function performing unsanitized string substitution of the 'premmerce_plugin_namespace' parameter directly into PHP stub files written to the wp-content/plugins/ directory. An attacker can inject a semicolon followed by arbitrary PHP code into the namespace parameter, causing the generated plugin file to contain and execute that code when accessed via HTTP. This makes it possible for authenticated attackers with Subscriber-level access and above to create arbitrary PHP files on the server and achieve remote code execution.

0.6% 2026-06-16
8.8 HIGH

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions throughΒ 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

0.3% 2026-06-16
8.8 HIGH

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action.

0.3% 2026-06-16
7.8 HIGH

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via the cypress_config_file configuration parameter. In readCypressConfigUtil.js, the loadJsFile() function constructs a shell command by interpolating the user-controlled cypress_config_filepath value into a template literal, then executes it via child_process.execSync(). Shell metacharacters in the config path (specifically " and ;) allow breaking out of the quoted argument and injecting arbitrary commands. This issue has been fixed in version 1.36.6.

0.5% 2026-06-15
8.8 HIGH

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with full process privileges, bypassing the require=null sandbox restriction. An authenticated user with basic access (no admin role, no run-shell-script permission required) can: execute arbitrary OS commands on the DbGate server with the privileges of the Node.js process, read/write any file accessible to the process, pivot to connected databases by reading connection credentials from DbGate's storage, and compromise the host system - in Docker deployments, this typically means root access within the container.

0.6% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

0.1% 2026-06-15
8.5 HIGH

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

0.2% 2026-06-15
8.5 HIGH

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

0.2% 2026-06-15
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

0.2% 2026-06-15
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

0.2% 2026-06-15
8.8 HIGH

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

0.2% 2026-06-15
7.5 HIGH

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

0.3% 2026-06-15
7.4 HIGH

Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

0.2% 2026-06-15
7.5 HIGH

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

0.4% 2026-06-15
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

0.3% 2026-06-15
8.2 HIGH

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

0.2% 2026-06-15
7.3 HIGH

Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.

0.2% 2026-06-15
7.5 HIGH

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

0.4% 2026-06-15
7.5 HIGH

Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.

0.3% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions.

0.2% 2026-06-15
8.1 HIGH

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

0.3% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.

0.2% 2026-06-15
8.5 HIGH

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

0.3% 2026-06-15
8.8 HIGH

Subscriber Privilege Escalation in Amelia <= 2.3 versions.

0.4% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.

0.2% 2026-06-15
7.5 HIGH

Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.

0.2% 2026-06-15
8.5 HIGH

Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

0.3% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.

0.2% 2026-06-15
8.5 HIGH

Subscriber SQL Injection in GamiPress <= 7.8.7 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.

0.2% 2026-06-15
7.5 HIGH

Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.

0.3% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.

0.2% 2026-06-15
7.5 HIGH

Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.

0.3% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.

0.2% 2026-06-15
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.

0.3% 2026-06-15
7.5 HIGH

Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.

0.3% 2026-06-15
7.5 HIGH

OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template engine uses a single shared text/template.Template instance (tpl package-level variable in service/internal/tpl/templates.go) across all goroutines. Every action execution calls tpl.Parse(source) followed by t.Execute() on this shared instance with no synchronization. When two or more actions execute concurrently (which is the normal case β€” each ExecRequest spawns a goroutine), a race condition occurs: one goroutine's Parse overwrites the template tree while another goroutine is calling Execute, causing cross-user command contamination, Go runtime panic, and incorrect command execution. This issue has been resolved in version 3000.13.0.

0.3% 2026-06-15
8.6 HIGH

Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).

0.2% 2026-06-15