CVE Browser

More filters (active)
CVE-2026-17509 MEDIUM

WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’

CVSS 6.5 EPSS 0.23% Sep 8, 2026
CVE-2026-12248 MEDIUM

WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection via 'sorting' Parameter

CVSS 6.5 EPSS 0.45% Aug 15, 2026
CVE-2025-3488 MEDIUM

WPML Multilingual CMS 3.6.0 - 4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpml_language_switcher Shortcode

CVSS 6.4 EPSS 0.30% May 2, 2025
CVE-2024-6386 CRITICAL

WPML Multilingual CMS <= 4.6.12 - Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection

CVSS 9.9 EPSS 25.53% Aug 21, 2024
CVE-2022-38974 MEDIUM

WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability

CVSS 4.3 EPSS 0.54% Nov 18, 2022
CVE-2022-38461 MEDIUM

WordPress WPML Multilingual CMS premium plugin <= 4.5.10 - Broken Access Control vulnerability

CVSS 5.4 EPSS 0.54% Nov 17, 2022
CVE-2022-45071 HIGH

WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability

CVSS 8.8 EPSS 0.32% Nov 17, 2022
CVE-2022-45072 MEDIUM

WordPress WPML Multilingual CMS premium plugin <= 4.5.13 - Cross-Site Request Forgery (CSRF) vulnerability

CVSS 4.3 EPSS 0.28% Nov 17, 2022
CVE-2018-18069 MEDIUM

process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter (such as locale_file_…

CVSS 6.1 EPSS 13.21% Oct 8, 2018
CVE-2015-2792 HIGH

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and per…

CVSS 7.5 EPSS 3.77% Mar 30, 2015
CVE-2015-2791 MEDIUM

The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a crafted reques…

CVSS 6.4 EPSS 13.29% Mar 30, 2015
CVE-2015-2315 MEDIUM

Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the t…

CVSS 4.3 EPSS 7.03% Mar 17, 2015
CVE-2015-2314 HIGH

SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in t…

CVSS 7.5 EPSS 7.07% Mar 17, 2015

Showing 1 to 13 CVEs · page 1