|
51
|
7.2 |
HIGH
Network
|
-
|
-
|
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateU…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-9851
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter in all versions up to, and i…
New
|
CWE-89
SQL Injection
|
CVE-2026-9829
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9594
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including, 2.5.0. This is due …
New
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-9016
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership v…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8839
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.4 via the 'invoice_id' parameter due to missing valid…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8611
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user i…
New
|
CWE-862
Missing Authorization
|
CVE-2026-7624
|
2026-06-6 14:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-11150
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Me…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-11148
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11146
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
61
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-362
Race Condition
|
CVE-2026-11145
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
62
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)
Update
|
CWE-416
Use After Free
|
CVE-2026-11144
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
63
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Out of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information…
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-11143
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
64
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-11142
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
65
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory v…
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11141
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
66
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process me…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11140
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
67
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-11139
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
68
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11138
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
69
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium securit…
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11137
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
70
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severi…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-11135
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
71
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-11134
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-11133
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-11132
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
Update
|
CWE-416
Use After Free
|
CVE-2026-11131
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-11129
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11119
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)
Update
|
CWE-416
Use After Free
|
CVE-2026-11116
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
7.3 |
HIGH
Local
|
-
|
-
|
Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Mediu…
Update
|
CWE-416
Use After Free
|
CVE-2026-11115
|
2026-06-6 14:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and including, 2.8.15 due to i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9280
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated…
New
|
CWE-22
Path Traversal
|
CVE-2026-9197
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
81
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_text' Settings in all versio…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8991
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.2.0 …
New
|
CWE-89
SQL Injection
|
CVE-2026-8978
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the 'retu…
New
|
CWE-862
Missing Authorization
|
CVE-2026-8502
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in al…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7796
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode 'num' parameter in all versions up to, and including, 4.38. This is due to ins…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7795
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to an…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-7792
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 6.6.4 via the ajax_load_mor…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7665
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
6.6 |
MEDIUM
Network
|
-
|
-
|
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.4 via deserialization of untrusted input . This makes it …
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7566
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Traversal in all versions up to, and including, 4.1.4 via the 'import-user-file' param…
New
|
CWE-22
Path Traversal
|
CVE-2026-7565
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
7.2 |
HIGH
Network
|
-
|
-
|
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type,…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7537
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
91
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename`…
New
|
CWE-22
Path Traversal
|
CVE-2026-2500
|
2026-06-6 13:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
Update
|
CWE-416
Use After Free
|
CVE-2026-11114
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape …
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11113
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a s…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11112
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
8.1 |
HIGH
Network
|
-
|
-
|
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11111
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11110
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-11109
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
8.8 |
HIGH
Network
|
-
|
-
|
Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: …
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-11108
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11107
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-11106
|
2026-06-6 13:17 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|