Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-63030 KEVEPSS 96%
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…
WordPress
6.9.5 / 7.0.2+
MEDIUM 5.9
CVE-2026-60137 KEVEPSS 73%
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…
WordPress
6.8.6 / 6.9.5+
MEDIUM 5.4
CVE-2022-4973
WordPress Core, in versions up to 6.0.2, is vulnerable to Authenticated Stored Cross-Site Scripting that can be exploited by users with access to the…
WordPress
after 6.0.2
HIGH 7.2
CVE-2024-8914
The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scr…
Thanh Toan Quet Ma Qr Code Tu Dong
after 2.0.1
MEDIUM 6.1
CVE-2024-4439EPSS 71%
WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insuffi…
WordPress
after 6.5.1
CRITICAL 9.8
CVE-2024-31211
WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__…
WordPress
6.4.2+
HIGH 8.8
CVE-2024-31210
WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an …
WordPress
4.1.40 / 4.2.37+
MEDIUM 5.3
CVE-2023-5561
WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email addre…
WordPress
4.7.27 / 4.8.23+
MEDIUM 5.4
CVE-2023-38000
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.…
WordPress
after 16.8.0
HIGH 8.8
CVE-2013-10027
A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/re…
Blogger Importer
0.6+
HIGH 8.8
CVE-2022-47174
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.
Performance Lab
after 2.2.0
HIGH 8.8
CVE-2022-47161
Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions.
Health Check \& Troubleshooting
after 1.5.1
MEDIUM 5.4
CVE-2023-2745EPSS 80%
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated a…
WordPress
4.1.38 / 4.2.35+
MEDIUM 6.1
CVE-2013-10021
A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the…
Debug Bar
0.8.1+
MEDIUM 5.3
CVE-2023-22622
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code…
WordPress
after 6.1.1
MEDIUM 5.9
CVE-2022-3590
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and …
WordPress
after 6.1.1
MEDIUM 6.1
CVE-2022-43497
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The d…
WordPress
3.7.40 / 3.8.40+
MEDIUM 6.1
CVE-2022-43500
Cross-site scripting vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to inject an arbitrary script. The d…
WordPress
3.7.40 / 3.8.40+
MEDIUM 5.3
CVE-2022-43504
Improper authentication vulnerability in WordPress versions prior to 6.0.3 allows a remote unauthenticated attacker to obtain the email address of th…
WordPress
3.7.40 / 3.8.40+
MEDIUM 6.5
CVE-2011-1762
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow…
WordPress
3.0.6 / 3.1.2+
HIGH 8.8
CVE-2022-21664
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization i…
WordPress
5.8.3+
HIGH 7.2
CVE-2022-21663
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Adm…
WordPress
5.8.3+
MEDIUM 5.4
CVE-2022-21662EPSS 65%
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (…
WordPress
5.8.3+
HIGH 7.5
CVE-2022-21661EPSS 98%
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Q…
WordPress
3.7.37 / 3.8.37+
CRITICAL 9.8
CVE-2021-44223EPSS 29%
WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply…
WordPress
5.8+
MEDIUM 6.5
CVE-2021-39203
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authen…
WordPress
Mitigation only
MEDIUM 5.4
CVE-2021-39201
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows…
WordPress
5.8+
MEDIUM 5.4
CVE-2021-39202
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions the wi…
WordPress
Mitigation only
MEDIUM 5.3
CVE-2021-39200
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output…
WordPress
5.8.1+
CRITICAL 9.8
CVE-2020-36326
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CV…
WordPress
3.7.36 / 3.8.36+