CVEs we hold for Web
Records whose assigning authority named Web as the affected vendor. Newest identifiers first, capped at 200.
Announced together
One group of these records was published under a single advisory. Its page names that advisory, counts what the group offers, and says what it does not cover.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
CVE-2026-9767The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameterweblizar The School Management – Education & Learning ERP
CVE-2026-9729Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…Webpushr
CVE-2026-9595webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxieswebpack-dev-server
CVE-2026-9017NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-9008Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode…webvitaly Page-list
CVE-2026-8853MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameterwebsoudan MW WP Form
CVE-2026-83596Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeatureWebKit; WebKitGTK; Red Hat Enterprise Linux 6…
CVE-2026-78376Webkitgtk: use-after-free of jscvalue function parametersWebKit; WebKitGTK; Red Hat Enterprise Linux 6…
CVE-2026-78291WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerabilityWebful Creations RepairBuddy
CVE-2026-77573Weblate: DNS rebinding in VCS operations allows server-side request forgeryWeblateOrg weblate
CVE-2026-77507Weblate: Object-scoped RSS feeds disclose private change history to unauthorized usersWeblateOrg weblate
CVE-2026-77006WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path TraversalUnknown WebTotem Backups
CVE-2026-76844webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPathwebpack-dev-middleware
CVE-2026-75961NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params'…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-75082Webkul Bagisto Customer-Registration Notification Email register cross site scriptingWebkul Bagisto
CVE-2026-7456Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect'…webocoders Udimi Tools
CVE-2026-73383WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerabilityWebAppick CTX Feed
CVE-2026-73339WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerabilityWebnus Inc. Modern Events Calendar
CVE-2026-7046NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table'…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-67595VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.phpwebreinvent vaahcms
CVE-2026-66709WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerabilityWebAppick CTX Feed
CVE-2026-65461WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerabilityWebの相談所 Really Simple CSV Importer
CVE-2026-6402webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS originswebpack-dev-server
CVE-2026-6396Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Actionwebarea Fast & Fancy Filter – 3F
CVE-2026-62249Weblate: Restricted-component change history leaked to non-member project users through the nested `GET…WeblateOrg weblate
CVE-2026-6206MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via…websoudan MW WP Form
CVE-2026-61978WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerabilitywebhosting4ugr Secure Card Gateway for ePay Paycenter…
CVE-2026-61792Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download…WeblateOrg weblate
CVE-2026-59804Midscene Bridge Server - Session Hijack via Unauthenticated WebSocketweb-infra-dev midscene
CVE-2026-57701WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerabilityWebCodingPlace Real Estate Manager Pro
CVE-2026-57398WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XSS) vulnerabilityWebCodingPlace Real Estate Manager Pro
CVE-2026-57345WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerabilityWebraketen Internal Links Manager
CVE-2026-55228Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private…WeblateOrg weblate
CVE-2026-55227Observable object existence disclosure in private Weblate projects via globally scoped object lookupsWeblateOrg weblate
CVE-2026-54501Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviorswebrecorder browsertrix
CVE-2026-5415WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Linkwebfactory Advanced Google reCAPTCHA
CVE-2026-5411WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Uploadwebfactory Advanced Google reCAPTCHA
CVE-2026-53779WebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on Windowswebp-sh webp_server_go
CVE-2026-5063NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Nameswebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-50127Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)WeblateOrg weblate
CVE-2026-49063WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerabilityWebilia Inc. Listdom
CVE-2026-49056WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.9.4 - Sensitive Data…WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery…
CVE-2026-48971WordPress Product Import Export for WooCommerce plugin <= 2.5.6 - Broken Access Control vulnerabilityWebToffee Product Import Export for WooCommerce
CVE-2026-48876WordPress Stop Spammers plugin <= 2026.3 - Cross Site Scripting (XSS) vulnerabilityWeb Guy Stop Spammers
CVE-2026-4852Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site…webzunft Image Source Control Lite – Show Image Credits and…
CVE-2026-45438WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Control vulnerabilityWebToffee Smart Coupons for WooCommerce
CVE-2026-4326Vertex Addons for Elementor <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin…webilia Vertex Addons for Elementor
CVE-2026-42150wlc: print_html outputs API data without HTML escaping, enabling stored XSSWeblateOrg wlc
CVE-2026-41654Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlWeblateOrg weblate
CVE-2026-40476graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validationwebonyx graphql-php
CVE-2026-40256Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionWeblateOrg weblate
CVE-2026-3998WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attributewebmindpt WM JqMath
CVE-2026-39675WordPress Court Reservation plugin <= 1.10.11 - Broken Access Control vulnerabilitywebmuehle Court Reservation
CVE-2026-39584WordPress RepairBuddy plugin <= 4.1132 - Broken Access Control vulnerabilityWebful Creations RepairBuddy
CVE-2026-39434WordPress CTX Feed plugin <= 6.6.26 - PHP Object Injection vulnerabilityWebAppick CTX Feed
CVE-2026-34895WordPress Softlab Core plugin < 1.2.11 - Local File Inclusion vulnerabilityWebGeniusLab Softlab Core
CVE-2026-34894WordPress Integrio Core plugin < 1.2.8 - Local File Inclusion vulnerabilityWebGeniusLab Integrio Core
CVE-2026-34893WordPress Thegov Core plugin < 2.0.23 - Local File Inclusion vulnerabilityWebGeniusLab Thegov Core
CVE-2026-33440Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsWeblateOrg weblate
CVE-2026-33220Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryWeblateOrg weblate
CVE-2026-32583WordPress Modern Events Calendar plugin <= 7.29.0 - Broken Access Control vulnerabilityWebnus Inc. Modern Events Calendar
CVE-2026-32441WordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerabilityWebToffee Comments Import & Export
CVE-2026-32439WordPress BigHearts theme <= 3.1.14 - Broken Access Control vulnerabilityWebGeniusLab BigHearts
CVE-2026-30964Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validationweb-auth webauthn-symfony-bundle
CVE-2026-27457Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsWeblateOrg weblate
CVE-2026-27409WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerabilityWebba Booking
CVE-2026-27399WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerabilityWebWizards MarketKing
CVE-2026-27361WordPress Responsive Posts Carousel Pro plugin <= 15.1 - Broken Access Control vulnerabilityWebCodingPlace Responsive Posts Carousel Pro
CVE-2026-27354WordPress WooCommerce Coming Soon Product with Countdown plugin <= 5.0 - Cross Site Scripting (XSS) vulnerabilityWebCodingPlace WooCommerce Coming Soon Product with…
CVE-2026-2714Institute Management <= 5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Enquiry Form Title'…weblizar Institute Management – Learning Management System
CVE-2026-25398WordPress Vertex Addons for Elementor plugin <= 1.6.4 - Broken Access Control vulnerabilityWebilia Inc. Vertex Addons for Elementor
CVE-2026-2487Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form'…weblizar Admin Custom Login
CVE-2026-24638WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerabilityWebful Creations RepairBuddy
CVE-2026-24606WordPress Bayarcash WooCommerce plugin <= 4.3.13 - Broken Access Control vulnerabilityWeb Impian Bayarcash WooCommerce
CVE-2026-24535WordPress Automatic Featured Images from Videos plugin <= 1.2.7 - Broken Access Control vulnerabilitywebdevstudios Automatic Featured Images from Videos
CVE-2026-2284News Element Elementor Blog Magazine <= 1.0.8 - Missing Authorization to Authenticated (Subscriber+) Data Losswebangon News Element Elementor Blog Magazine
CVE-2026-22480WordPress Product Feed for WooCommerce plugin <= 2.3.3 - PHP Object Injection vulnerabilityWebToffee Product Feed for WooCommerce
CVE-2026-22461WordPress CTX Feed plugin <= 6.6.18 - Broken Access Control vulnerabilityWebAppick CTX Feed
CVE-2026-2112Dam Spam <= 1.0.8 - Cross-Site Request Forgery to Arbitrary Pending Comment Deletionwebguyio Dam Spam
CVE-2026-19996Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges managementWebkul Bagisto
CVE-2026-19834Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorizationWebkul Bagisto
CVE-2026-19796Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthenticated Stored Cross-Site…webilia Listdom: AI-powered Business Directory with…
CVE-2026-1948NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-1947NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-18027WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated…WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery…
CVE-2026-15602NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Parameterwebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-15450NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameterwebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-15142Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID…WebCodingPlace Real Estate Manager Pro
CVE-2026-14894Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)WebRehab Super Forms – Drag & Drop Form Builder
CVE-2026-14631webpack-dev-server vulnerable to denial of service via a malformed Host or Origin headerwebpack-dev-server
CVE-2026-14620webpack-dev-server vulnerable to cross-site request forgery via internal developer endpointswebpack-dev-server
CVE-2026-14352AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameterwebandprint AR for WooCommerce
CVE-2026-14327AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameterwebandprint AR for WordPress
CVE-2026-13389WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via…Unknown webtoffee-cookie-consent
CVE-2026-13040NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameterwebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-1250Court Reservation – Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injectionwebmuehle Court Reservation – Manage Your Court Bookings…
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.