CVE-2026-97288 - WordPress OAuth Server plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97288
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97288
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97289 - WordPress Quiz And Survey Master plugin <= 11.2.6 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97289
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97289
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97292 - WordPress YITH WooCommerce Tab Manager plugin <= 2.15.0 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97292
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97292
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97293 - WordPress Media LIbrary Assistant plugin <= 3.41 - SQL Injection vulnerability
CVE ID :CVE-2026-97293
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97293
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97298 - WordPress King Addons for Elementor plugin <= 51.1.86 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97298
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97298
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97299 - WordPress Razorpay Payment Links for WooCommerce plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-97299
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97299
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97301 - WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-97301
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97301
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-97302 - WordPress MPG plugin <= 4.2.3 - Sensitive Data Exposure vulnerability
CVE ID :CVE-2026-97302
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-97302
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Sensitive Data Exposure in MPG <= 4.2.3 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100507 - WordPress If-So Dynamic Content Personalization plugin <= 1.10.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-100507
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100507
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100508 - WordPress Two Factor plugin <= 0.16.0 - Denial of Service Attack vulnerability
CVE ID :CVE-2026-100508
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100508
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-100513 - WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin <= 3.2.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-100513
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-100513
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102384 - WordPress Supreme Modules Lite plugin <= 2.5.63 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102384
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102384
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102385 - WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102385
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102385
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102386 - WordPress WP Photo Album Plus plugin <= 9.3.02.003 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102386
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102386
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102395 - WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102395
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102395
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102396 - WordPress Ultimate Maps by Supsystic plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102396
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102396
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102398 - WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability
CVE ID :CVE-2026-102398
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102398
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102399 - WordPress Photo Gallery by Supsystic plugin <= 1.21.0 - Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-102399
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-102399
Published : Sept. 30, 2026, 12:28 p.m. | 1 hour, 1 minute ago
Description :Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103116 - OS4ED openSIS-Classic Student List Search Endpoint GetStuListFnc.php DBQuery sql injection
CVE ID :CVE-2026-103116
Published : Sept. 30, 2026, 12:45 p.m. | 45 minutes ago
Description :A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103116
Published : Sept. 30, 2026, 12:45 p.m. | 45 minutes ago
Description :A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-86778 - Username Enumeration in Maksisoft Technology's Maksisoft Gym
CVE ID :CVE-2026-86778
Published : Sept. 30, 2026, 12:59 p.m. | 30 minutes ago
Description :Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-86778
Published : Sept. 30, 2026, 12:59 p.m. | 30 minutes ago
Description :Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from 0.5.10 before 0.5.11.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-103117 - OS4ED openSIS-Classic Save Data DatabaseInc.php db_properties sql injection
CVE ID :CVE-2026-103117
Published : Sept. 30, 2026, 1 p.m. | 29 minutes ago
Description :A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-103117
Published : Sept. 30, 2026, 1 p.m. | 29 minutes ago
Description :A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...