CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-92727 MEDIUM

EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slidesShow' Block Attribute

CVSS 6.4 EPSS n/a Oct 3, 2026
CVE-2026-96256 MEDIUM

Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute

CVSS 6.4 EPSS 0.29% Oct 1, 2026
CVE-2026-89330 MEDIUM

EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters

CVSS 6.1 EPSS 0.37% Sep 18, 2026
CVE-2026-75980 MEDIUM

BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content

CVSS 6.4 EPSS 0.35% Sep 1, 2026
CVE-2026-19801 MEDIUM

BetterLinks <= 3.1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action

CVSS 4.3 EPSS 0.29% Aug 25, 2026
CVE-2026-18438 HIGH

Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch

CVSS 8.8 EPSS 1.31% Aug 15, 2026
CVE-2026-15145 MEDIUM

Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget

CVSS 6.4 EPSS 0.42% Jul 21, 2026
CVE-2026-15156 MEDIUM

Essential Addons for Elementor <= 6.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings

CVSS 6.4 EPSS 0.35% Jul 21, 2026
CVE-2026-15155 HIGH

Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection

CVSS 8.8 EPSS 0.67% Jul 11, 2026
CVE-2026-15104 MEDIUM

BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter

CVSS 6.5 EPSS 0.41% Jul 10, 2026
CVE-2026-6459 MEDIUM

Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup

CVSS 6.4 EPSS 0.32% Jul 8, 2026
CVE-2026-10833 MEDIUM

Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurable…

CVSS 6.4 EPSS 0.33% Jun 25, 2026
CVE-2026-12157 MEDIUM

BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute

CVSS 6.4 EPSS 0.35% Jun 19, 2026
CVE-2026-7796 MEDIUM

EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute

CVSS 6.4 EPSS 0.42% Jun 6, 2026
CVE-2026-7665 MEDIUM

Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler

CVSS 5.3 EPSS 0.56% Jun 6, 2026
CVE-2026-10586 HIGH

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery

CVSS 7.2 EPSS 0.26% Jun 4, 2026
CVE-2026-5193 MEDIUM

Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user

CVSS 6.5 EPSS 0.31% May 14, 2026
CVE-2026-4658 MEDIUM

Gutenberg Essential Blocks <= 6.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes

CVSS 6.4 EPSS 0.42% May 2, 2026
CVE-2026-6393 MEDIUM

BetterDocs <= 4.3.11 - Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage

CVSS 4.3 EPSS 0.35% Apr 24, 2026
CVE-2026-3875 MEDIUM

BetterDocs <= 4.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

CVSS 6.4 EPSS 0.26% Apr 16, 2026
CVE-2026-1512 MEDIUM

Essential Addons for Elementor <= 6.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Info Box Widget

CVSS 6.4 EPSS 0.24% Feb 14, 2026
CVE-2026-0554 MEDIUM

NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset

CVSS 4.3 EPSS 0.30% Jan 20, 2026
CVE-2025-15380 HIGH

NotificationX <= 3.2.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview'

CVSS 7.2 EPSS 0.28% Jan 20, 2026
CVE-2026-1004 MEDIUM

Essential Addons for Elementor <= 6.5.5 - Missing Authorization to Unauthenticated Sensitive Information Exposure

CVSS 5.3 EPSS 0.38% Jan 16, 2026
CVE-2026-0831 MEDIUM

Templately <= 3.4.8 - Unauthenticated Limited Arbitrary JSON File Write

CVSS 5.3 EPSS 0.27% Jan 10, 2026

Showing 1 to 25 CVEs · page 1 (more available)