CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-14229 - The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when renderi
CVE-2026-18387 - The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to ge
CVE-2026-17090 - The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable t
CVE-2026-16586 - The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is
CVE-2026-16146 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln
CVE-2026-16145 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln
CVE-2026-16094 - The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vuln
CVE-2026-15993 - The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is v
CVE-2026-15948 - The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to
CVE-2026-15453 - The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generi
CVE-2026-8840 - The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization
CVE-2026-16080 - The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the '
CVE-2026-15965 - The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnera
CVE-2026-15341 - The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to
CVE-2026-15312 - The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege
CVE-2026-15303 - The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to,
CVE-2026-15162 - The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpre
CVE-2026-15001 - The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalatio
CVE-2026-14484 - The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arb
CVE-2026-14433 - The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable t
CVE-2026-12128 - The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via
CVE-2026-42726 - Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds
CVE-2026-3349 - The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t
CVE-2026-3348 - The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-2288 - The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_titl
CVE-2026-2280 - The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings
CVE-2025-0898 - The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all
CVE-2026-8942 - The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver
CVE-2026-8906 - The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up
CVE-2026-8832 - The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for W
CVE-2026-8143 - The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso'
CVE-2026-8042 - The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo
CVE-2026-7618 - The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based bl
CVE-2026-6169 - The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up
CVE-2026-3897 - The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scrip
CVE-2026-3896 - The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
CVE-2026-3895 - The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-3375 - The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-js
CVE-2026-3279 - The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of
CVE-2026-3001 - The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' para
CVE-2026-2030 - The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-9200 - The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to
CVE-2026-9014 - The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a mis
CVE-2026-8994 - The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up t
CVE-2026-8943 - The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
CVE-2026-8941 - The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up
CVE-2026-8939 - The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in version
CVE-2026-8938 - The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
CVE-2026-8911 - The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up
CVE-2026-8903 - The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site R
CVE-2026-8899 - The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbn
CVE-2026-8898 - The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-ev
CVE-2026-8897 - The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode
CVE-2026-8894 - The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `
CVE-2026-8891 - The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitf
CVE-2026-8887 - The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'list
CVE-2026-8886 - The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-pl
CVE-2026-8884 - The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
CVE-2026-8877 - The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via
CVE-2026-8875 - The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-8873 - The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcod
CVE-2026-8872 - The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p
CVE-2026-8871 - The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ki
CVE-2026-8870 - The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cros
CVE-2026-8869 - The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tit
CVE-2026-8868 - The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sing
CVE-2026-8867 - The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE-2026-8847 - The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo'
CVE-2026-8846 - The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' sh
CVE-2026-8845 - The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'isla
CVE-2026-8844 - The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspc
CVE-2026-8837 - The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Sit
CVE-2026-8787 - The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in
CVE-2026-8760 - The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to
CVE-2026-8708 - The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi
CVE-2026-8707 - The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via P
CVE-2026-8703 - The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode A
CVE-2026-8702 - The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 vi
CVE-2026-8701 - The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers
CVE-2026-8698 - The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-8048 - The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'su
CVE-2026-8040 - The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color'
CVE-2026-7614 - The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve
CVE-2026-6268 - The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eve
CVE-2026-9236 - The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress i
CVE-2026-6287 - The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to
CVE-2025-14481 - The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all version
CVE-2026-9022 - The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url
CVE-2026-7493 - The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress
CVE-2026-6565 - The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for
CVE-2026-8174 - Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue
CVE-2018-25352 - WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulner
CVE-2018-25347 - WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authen
CVE-2018-25346 - WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow auth
CVE-2026-9284 - The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulatio
CVE-2026-6898 - The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a
CVE-2026-6897 - The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a
CVE-2026-6895 - The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive
CVE-2026-6419 - The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authoriza
CVE-2026-9011 - The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to author
CVE-2026-8692 - The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPr
CVE-2026-8684 - The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versio
CVE-2026-8679 - The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions
CVE-2026-7798 - The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and C
CVE-2026-7636 - The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable t
CVE-2026-7615 - The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
CVE-2026-9104 - The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Titl
CVE-2026-9018 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to P
CVE-2026-7509 - The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
CVE-2026-7249 - The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to
CVE-2026-6864 - The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting
CVE-2026-4070 - The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
CVE-2026-3481 - The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortc
CVE-2026-2518 - The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activati
CVE-2026-4834 - The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in
CVE-2026-6960 - The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil
CVE-2026-5118 - The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to,
CVE-2026-6279 - The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code
CVE-2026-1543 - The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mul
CVE-2026-4811 - The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress
CVE-2026-1881 - The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versio
CVE-2026-7613 - The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting
CVE-2026-6728 - The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versio
CVE-2026-9065 - SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameter
CVE-2026-6405 - The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Req
CVE-2026-5200 - The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugi
CVE-2026-7385 - The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email a
CVE-2026-6566 - The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable
CVE-2026-5776 - The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user
CVE-2026-2955 - The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site
CVE-2026-7522 - The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion i
CVE-2026-5075 - The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'interna
CVE-2026-9010 - The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and '
CVE-2026-7637 - The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin
CVE-2025-15369 - The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modi
CVE-2026-8685 - The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order
CVE-2026-8627 - The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SE
CVE-2026-8626 - The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Para
CVE-2026-8624 - The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin
CVE-2026-8610 - The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all
CVE-2026-8424 - The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers
CVE-2026-8423 - The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in a
CVE-2026-8420 - The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver
CVE-2026-8419 - The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions
CVE-2026-8418 - The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to
CVE-2026-8038 - The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'defaul
CVE-2026-7472 - The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via t
CVE-2026-7467 - The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions
CVE-2026-7462 - The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `pa
CVE-2026-7284 - The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to p
CVE-2026-6555 - The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up
CVE-2026-6549 - The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th
CVE-2026-6456 - The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up t
CVE-2026-6452 - The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v
CVE-2026-6404 - The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-S
CVE-2026-6401 - The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t
CVE-2026-6400 - The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request For
CVE-2026-6399 - The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up
CVE-2026-6397 - The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` s
CVE-2026-6395 - The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored C
CVE-2026-6391 - The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Sit
CVE-2026-6072 - The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorizati
CVE-2026-5293 - The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Sc
CVE-2026-3985 - The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerabl
CVE-2026-8096 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-8073 - The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t
CVE-2026-8912 - The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' paramet
CVE-2026-4883 - The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file ty
CVE-2026-4885 - The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due
CVE-2025-15609 - The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthentica
CVE-2026-6495 - The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before ou
CVE-2026-6381 - The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in
CVE-2026-6379 - The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a p
CVE-2026-3220 - The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed
CVE-2026-1631 - The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.