CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-11895 MEDIUM

HT Mega Addons for Elementor <= 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting

CVSS 6.4 EPSS 0.16% Sep 30, 2026
CVE-2026-92554 MEDIUM

ShopLentor <= 3.5.1 - Reflected Cross-Site Scripting via Query-String Parameter Name

CVSS 6.1 EPSS 0.37% Sep 18, 2026
CVE-2026-19806 HIGH

Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token

CVSS 8.8 EPSS 0.40% Sep 1, 2026
CVE-2026-6020 HIGH

ShopLentor <= 3.3.7 - Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API

CVSS 7.2 EPSS 0.78% Aug 5, 2026
CVE-2026-16811 MEDIUM

ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

CVSS 4.9 EPSS 0.44% Jul 28, 2026
CVE-2026-16797 MEDIUM

ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter

CVSS 4.3 EPSS 0.38% Jul 28, 2026
CVE-2026-12936 MEDIUM

Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Parameter

CVSS 4.9 EPSS 0.44% Jul 8, 2026
CVE-2026-6287 MEDIUM

ShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' B…

CVSS 5.4 EPSS 0.24% May 27, 2026
CVE-2026-4059 MEDIUM

ShopLentor <= 3.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute

CVSS 6.4 EPSS 0.35% Apr 14, 2026
CVE-2026-1714 HIGH

ShopLentor <= 3.3.2 - Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action

CVSS 8.6 EPSS 0.67% Feb 18, 2026
CVE-2025-13141 MEDIUM

HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection

CVSS 6.4 EPSS 0.21% Nov 21, 2025
CVE-2025-12493 CRITICAL

ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template'

CVSS 9.8 EPSS 0.77% Nov 4, 2025
CVE-2025-11823 MEDIUM

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scriptin…

CVSS 6.4 EPSS 0.22% Oct 25, 2025
CVE-2025-8068 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Improper Authorization to Authenticated (Contributor+) Limited Administrator Actions

CVSS 4.3 EPSS 0.31% Jul 31, 2025
CVE-2025-8401 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Sensitive Information Exposure

CVSS 4.3 EPSS 0.34% Jul 31, 2025
CVE-2025-8151 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions

CVSS 4.3 EPSS 0.40% Jul 31, 2025
CVE-2025-3775 MEDIUM

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Reques…

CVSS 6.5 EPSS 0.28% Apr 25, 2025
CVE-2025-1802 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets

CVSS 6.4 EPSS 0.29% Mar 20, 2025
CVE-2025-1527 MEDIUM

ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Store…

CVSS 6.4 EPSS 0.26% Mar 12, 2025
CVE-2025-1261 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget

CVSS 6.4 EPSS 0.22% Mar 8, 2025
CVE-2024-12599 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget

CVSS 6.4 EPSS 0.34% Feb 11, 2025
CVE-2024-12597 MEDIUM

HT Mega <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via block_css and inner_css

CVSS 6.4 EPSS 0.32% Feb 4, 2025
CVE-2024-13216 MEDIUM

HT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: Sponsor

CVSS 4.3 EPSS 0.32% Jan 31, 2025
CVE-2024-9538 MEDIUM

ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template

CVSS 6.5 EPSS 0.40% Oct 11, 2024
CVE-2024-8910 MEDIUM

HT Mega – Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_id

CVSS 4.3 EPSS 0.31% Sep 25, 2024

Showing 1 to 25 CVEs · page 1 (more available)