vciy

CVEs we hold for Web

Records whose assigning authority named Web as the affected vendor. Newest identifiers first, capped at 200.

Announced together

One group of these records was published under a single advisory. Its page names that advisory, counts what the group offers, and says what it does not cover.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-9767The School Management <= 5.4 - Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameterweblizar The School Management – Education & Learning ERP
CVE-2026-9729Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via…Webpushr
CVE-2026-9595webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxieswebpack-dev-server
CVE-2026-9506Path Traversal Vulnerability in BagistoWebkul Bagisto
CVE-2026-93454Aureus ERP through 1.6.0 Stored XSS via Payment Term NoteWebkul Aureus ERP
CVE-2026-92234QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation ErrorsWebkul QloApps
CVE-2026-90648no title heldWebAssembly wabt
CVE-2026-90492webgjc web_robot web.py controller_recover os command injectionwebgjc web_robot
CVE-2026-9017NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-9008Page-list <= 6.2 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode…webvitaly Page-list
CVE-2026-89268QloApps through 1.7.0 Reflected XSS via List Filter ParametersWebkul QloApps
CVE-2026-8853MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameterwebsoudan MW WP Form
CVE-2026-86119Webstudio through 0.296.0 SSRF via /cgi proxy routeswebstudio-is webstudio
CVE-2026-83596Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeatureWebKit; WebKitGTK; Red Hat Enterprise Linux 6…
CVE-2026-8315Stored XSS in Webbeyaz's Mediküm WebWebbeyaz Web Design Mediküm Web
CVE-2026-8310Reflected XSS in Webbeyaz's Mediküm WebWebbeyaz Web Design Mediküm Web
CVE-2026-8307SQLi in Webbeyaz's Mediküm WebWebbeyaz Web Design Mediküm Web
CVE-2026-8257WebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertionWebAssembly Binaryen
CVE-2026-78376Webkitgtk: use-after-free of jscvalue function parametersWebKit; WebKitGTK; Red Hat Enterprise Linux 6…
CVE-2026-78291WordPress RepairBuddy plugin <= 4.1223 - Broken Access Control vulnerabilityWebful Creations RepairBuddy
CVE-2026-77573Weblate: DNS rebinding in VCS operations allows server-side request forgeryWeblateOrg weblate
CVE-2026-77508Weblate: Unverified REST API email changesWeblateOrg weblate
CVE-2026-77507Weblate: Object-scoped RSS feeds disclose private change history to unauthorized usersWeblateOrg weblate
CVE-2026-77006WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path TraversalUnknown WebTotem Backups
CVE-2026-76844webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPathwebpack-dev-middleware
CVE-2026-75961NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params'…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-75498Webkul QloApps SQL injectionWebkul QloApps
CVE-2026-75497Webkul QloApps SQL injectionWebkul QloApps
CVE-2026-75496Webkul QloApps improper file upload validationWebkul QloApps
CVE-2026-75082Webkul Bagisto Customer-Registration Notification Email register cross site scriptingWebkul Bagisto
CVE-2026-75081Webkul Bagisto store behavioral workflowWebkul Bagisto
CVE-2026-7456Udimi Tools <= 3.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect'…webocoders Udimi Tools
CVE-2026-73383WordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerabilityWebAppick CTX Feed
CVE-2026-73339WordPress Modern Events Calendar plugin < 7.35.0 - SQL Injection vulnerabilityWebnus Inc. Modern Events Calendar
CVE-2026-7046NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table'…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-68491no title heldWebpros SolusVM
CVE-2026-68489no title heldWebPros Plesk extension "Node.js Toolkit"
CVE-2026-68488no title heldWebPros Plesk
CVE-2026-68487no title heldWebPros Plesk
CVE-2026-67595VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.phpwebreinvent vaahcms
CVE-2026-6743WebSystems WebTOTUM Calendar cross site scriptingWebSystems WebTOTUM
CVE-2026-67402no title heldWebPros ConfigServer Security & Firewall…
CVE-2026-67401no title heldWebPros cPanel
CVE-2026-67399no title heldWebPros WHMCS
CVE-2026-67398no title heldWebPros WHMCS
CVE-2026-67397no title heldWebPros Plesk
CVE-2026-67394no title heldWebPros Plesk
CVE-2026-66709WordPress CTX Feed plugin <= 6.6.42 - Remote Code Execution (RCE) vulnerabilityWebAppick CTX Feed
CVE-2026-65647no title heldWebPros Plesk Site Import
CVE-2026-65646no title heldWebPros Plesk
CVE-2026-65643no title heldWebPros cPanel
CVE-2026-65642no title heldWebPros Plesk
CVE-2026-65639no title heldWebPros ConfigServer Security & Firewall…
CVE-2026-65638no title heldWebPros ConfigServer Security & Firewall…
CVE-2026-65461WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerabilityWebの相談所 Really Simple CSV Importer
CVE-2026-64639no title heldWebPros Plesk
CVE-2026-64637no title heldWebPros Plesk
CVE-2026-64636no title heldWebPros Plesk
CVE-2026-6402webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS originswebpack-dev-server
CVE-2026-6396Fast & Fancy Filter – 3F <= 1.2.2 - Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Actionwebarea Fast & Fancy Filter – 3F
CVE-2026-62326Weblate Has Uncontrolled Resource Consumption viaWeblateOrg weblate
CVE-2026-62249Weblate: Restricted-component change history leaked to non-member project users through the nested `GET…WeblateOrg weblate
CVE-2026-6206MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via…websoudan MW WP Form
CVE-2026-61978WordPress Secure Card Gateway for ePay Paycenter (Piraeus Bank) plugin <= 1.0.32 - Broken Access Control vulnerabilitywebhosting4ugr Secure Card Gateway for ePay Paycenter…
CVE-2026-61969WordPress Listdom plugin <= 5.6.0 - SQL Injection vulnerabilityWebilia Inc. Listdom
CVE-2026-61792Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download…WeblateOrg weblate
CVE-2026-61790Weblate: Team-enforced 2FA is bypassed for global permissionsWeblateOrg weblate
CVE-2026-61524WebsiteBaker CMS < 2.13.10 File Upload RCE via Module InstallationWebsiteBaker CMS
CVE-2026-61523WebsiteBaker CMS < 2.13.10 Code Injection via Droplets EditorWebsiteBaker CMS
CVE-2026-60120Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.phpWebkul Bagisto
CVE-2026-59804Midscene Bridge Server - Session Hijack via Unauthenticated WebSocketweb-infra-dev midscene
CVE-2026-58048no title heldWebPros WP Squared
CVE-2026-58047no title heldWebPros WP Squared
CVE-2026-58046no title heldWebPros Plesk
CVE-2026-57701WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerabilityWebCodingPlace Real Estate Manager Pro
CVE-2026-57398WordPress Real Estate Manager Pro plugin <= 12.8.3 - Cross Site Scripting (XSS) vulnerabilityWebCodingPlace Real Estate Manager Pro
CVE-2026-57345WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerabilityWebraketen Internal Links Manager
CVE-2026-56843no title heldWebpros Plesk
CVE-2026-56022Webmin MFA bypassWebmin
CVE-2026-56021Webmin information disclosure via regex patternWebmin
CVE-2026-56020Webmin HTTP header authentication bypassWebmin
CVE-2026-55228Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private…WeblateOrg weblate
CVE-2026-55227Observable object existence disclosure in private Weblate projects via globally scoped object lookupsWeblateOrg weblate
CVE-2026-54819WordPress Listdom plugin <= 5.4.0 - SQL Injection vulnerabilityWebilia Inc. Listdom
CVE-2026-54501Browsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom Behaviorswebrecorder browsertrix
CVE-2026-5415WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Linkwebfactory Advanced Google reCAPTCHA
CVE-2026-5411WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Uploadwebfactory Advanced Google reCAPTCHA
CVE-2026-53779WebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on Windowswebp-sh webp_server_go
CVE-2026-5063NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Nameswebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-50127Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)WeblateOrg weblate
CVE-2026-49103no title heldWebmin
CVE-2026-49102no title heldWebmin
CVE-2026-49063WordPress Listdom plugin <= 5.5.0 - Privilege Escalation vulnerabilityWebilia Inc. Listdom
CVE-2026-49056WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.9.4 - Sensitive Data…WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery…
CVE-2026-48971WordPress Product Import Export for WooCommerce plugin <= 2.5.6 - Broken Access Control vulnerabilityWebToffee Product Import Export for WooCommerce
CVE-2026-48876WordPress Stop Spammers plugin <= 2026.3 - Cross Site Scripting (XSS) vulnerabilityWeb Guy Stop Spammers
CVE-2026-48779ws: Memory exhaustion DoS from tiny fragments and data chunkswebsockets ws
CVE-2026-48614no title heldWebPros Plesk
CVE-2026-4852Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site…webzunft Image Source Control Lite – Show Image Credits and…
CVE-2026-47365no title heldWebPros WordPress-Toolkit
CVE-2026-45819no title heldweb-platform-dx baseline-browser-mapping
CVE-2026-45736ws: Uninitialized memory disclosurewebsockets ws
CVE-2026-45438WordPress Smart Coupons for WooCommerce plugin < 2.3.0 - Broken Access Control vulnerabilityWebToffee Smart Coupons for WooCommerce
CVE-2026-45106Weblate: Stored HTML injection in editor search previewWeblateOrg weblate
CVE-2026-44962no title heldWebPros Plesk
CVE-2026-44264Weblate is vulnerable to XSS via crafted MarkdownWeblateOrg weblate
CVE-2026-44263Weblate: Private Translation Enumeration via Screenshot APIWeblateOrg weblate
CVE-2026-4326Vertex Addons for Elementor <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin…webilia Vertex Addons for Elementor
CVE-2026-42210Webmin 2FA requirement bypasswebmin
CVE-2026-42150wlc: print_html outputs API data without HTML escaping, enabling stored XSSWeblateOrg wlc
CVE-2026-41940WebPros cPanel and WHM Authentication Bypass via Login FlowWebPros WHM
CVE-2026-41654Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlWeblateOrg weblate
CVE-2026-41519Weblate's API Token Not Invalidated on Password ChangeWeblateOrg weblate
CVE-2026-40476graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validationwebonyx graphql-php
CVE-2026-40256Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionWeblateOrg weblate
CVE-2026-3998WM JqMath <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attributewebmindpt WM JqMath
CVE-2026-39845Weblate: SSRF via the webhook add-on using unprotected fetch_url()WeblateOrg weblate
CVE-2026-39675WordPress Court Reservation plugin <= 1.10.11 - Broken Access Control vulnerabilitywebmuehle Court Reservation
CVE-2026-39584WordPress RepairBuddy plugin <= 4.1132 - Broken Access Control vulnerabilityWebful Creations RepairBuddy
CVE-2026-39434WordPress CTX Feed plugin <= 6.6.26 - PHP Object Injection vulnerabilityWebAppick CTX Feed
CVE-2026-34895WordPress Softlab Core plugin < 1.2.11 - Local File Inclusion vulnerabilityWebGeniusLab Softlab Core
CVE-2026-34894WordPress Integrio Core plugin < 1.2.8 - Local File Inclusion vulnerabilityWebGeniusLab Integrio Core
CVE-2026-34893WordPress Thegov Core plugin < 2.0.23 - Local File Inclusion vulnerabilityWebGeniusLab Thegov Core
CVE-2026-34393Weblate: Privilege escalation in the user API endpointWeblateOrg weblate
CVE-2026-34244Weblate: SSRF via Project-Level Machinery ConfigurationWeblateOrg weblate
CVE-2026-34242Weblate: Arbitrary File Read via SymlinkWeblateOrg weblate
CVE-2026-33440Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsWeblateOrg weblate
CVE-2026-33435Weblate: Remote code execution during backup restorationWeblateOrg weblate
CVE-2026-33228flatted: Prototype Pollution via parse()WebReflection flatted
CVE-2026-33220Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryWeblateOrg weblate
CVE-2026-33214Weblate has improper access control for the translation memory APIWeblateOrg weblate
CVE-2026-33212Weblate: Improper access control for pending tasks in APIWeblateOrg weblate
CVE-2026-32999no title heldWebPros Comet Backup
CVE-2026-32993no title heldWebPros WP Squared
CVE-2026-32992no title heldWebPros WP Squared
CVE-2026-32991no title heldWebPros cPanel (CloudLinux 6, CentOS 6)
CVE-2026-32583WordPress Modern Events Calendar plugin <= 7.29.0 - Broken Access Control vulnerabilityWebnus Inc. Modern Events Calendar
CVE-2026-3251XSS in Webremium's Mezunum SatiyorumWebremium Istanbul Web Design Mezunum Satiyorum
CVE-2026-32441WordPress Comments Import & Export plugin <= 2.4.9 - Broken Access Control vulnerabilityWebToffee Comments Import & Export
CVE-2026-32439WordPress BigHearts theme <= 3.1.14 - Broken Access Control vulnerabilityWebGeniusLab BigHearts
CVE-2026-32141flatted: Unbounded recursion DoS in parse() revive phaseWebReflection flatted
CVE-2026-30964Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validationweb-auth webauthn-symfony-bundle
CVE-2026-29206no title heldWebPros cPanel (CloudLinux 6, CentOS 6)
CVE-2026-29205no title heldWebPros WP Squared
CVE-2026-29204no title heldWebPros WHMCS
CVE-2026-29203no title heldWebPros WP Squared
CVE-2026-29202no title heldWebPros WP Squared
CVE-2026-29201no title heldWebPros cPanel (CloudLinux 6, CentOS 6)
CVE-2026-29200no title heldWebPros Comet Backup
CVE-2026-27457Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsWeblateOrg weblate
CVE-2026-27409WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerabilityWebba Booking
CVE-2026-27399WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerabilityWebWizards MarketKing
CVE-2026-27361WordPress Responsive Posts Carousel Pro plugin <= 15.1 - Broken Access Control vulnerabilityWebCodingPlace Responsive Posts Carousel Pro
CVE-2026-27354WordPress WooCommerce Coming Soon Product with Countdown plugin <= 5.0 - Cross Site Scripting (XSS) vulnerabilityWebCodingPlace WooCommerce Coming Soon Product with…
CVE-2026-2714Institute Management <= 5.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Enquiry Form Title'…weblizar Institute Management – Learning Management System
CVE-2026-25398WordPress Vertex Addons for Elementor plugin <= 1.6.4 - Broken Access Control vulnerabilityWebilia Inc. Vertex Addons for Elementor
CVE-2026-25244WebdriverIO has Command Injection in the BrowserStack Servicewebdriverio
CVE-2026-25198no title heldweb2py
CVE-2026-2487Admin Custom Login <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form'…weblizar Admin Custom Login
CVE-2026-24638WordPress RepairBuddy plugin <= 4.1121 - Broken Access Control vulnerabilityWebful Creations RepairBuddy
CVE-2026-24606WordPress Bayarcash WooCommerce plugin <= 4.3.13 - Broken Access Control vulnerabilityWeb Impian Bayarcash WooCommerce
CVE-2026-24536WordPress Webpushr plugin <= 4.38.0 - Sensitive Data Exposure vulnerabilityWebpushr
CVE-2026-24535WordPress Automatic Featured Images from Videos plugin <= 1.2.7 - Broken Access Control vulnerabilitywebdevstudios Automatic Featured Images from Videos
CVE-2026-24126Weblate has an argument injection in management consoleWeblateOrg weblate
CVE-2026-23535wlc Path traversal: Unsanitized API slugs in download commandWeblateOrg wlc
CVE-2026-2284News Element Elementor Blog Magazine <= 1.0.8 - Missing Authorization to Authenticated (Subscriber+) Data Losswebangon News Element Elementor Blog Magazine
CVE-2026-22678Webmin < 2.641 Stored XSS via System and Server StatusWebmin
CVE-2026-22480WordPress Product Feed for WooCommerce plugin <= 2.3.3 - PHP Object Injection vulnerabilityWebToffee Product Feed for WooCommerce
CVE-2026-22461WordPress CTX Feed plugin <= 6.6.18 - Broken Access Control vulnerabilityWebAppick CTX Feed
CVE-2026-22251wlc may leak API keys due to an insecure API key configurationWeblateOrg wlc
CVE-2026-22250wlc can skip SSL verificationWeblateOrg wlc
CVE-2026-21889Weblate leaks information via screenshotsWeblateOrg weblate
CVE-2026-2112Dam Spam <= 1.0.8 - Cross-Site Request Forgery to Arbitrary Pending Comment Deletionwebguyio Dam Spam
CVE-2026-19997Webkul Bagisto Backend Sales RMA Endpoint requests authorizationWebkul Bagisto
CVE-2026-19996Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges managementWebkul Bagisto
CVE-2026-19995Webkul Bagisto RMA Message send-message cross site scriptingWebkul Bagisto
CVE-2026-19994Webkul Bagisto Configuration Management execute authorizationWebkul Bagisto
CVE-2026-19993Webkul Bagisto RMA State Validation update-status behavioral workflowWebkul Bagisto
CVE-2026-19838Webkul Bagisto Backend Reporting Endpoint sales authorizationWebkul Bagisto
CVE-2026-19837Webkul Bagisto Customer Search search information disclosureWebkul Bagisto
CVE-2026-19836Webkul Bagisto Backend Customer Detail Feature view authorizationWebkul Bagisto
CVE-2026-19835Webkul Bagisto Customer Item Deletion Endpoint access controlWebkul Bagisto
CVE-2026-19834Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorizationWebkul Bagisto
CVE-2026-19796Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthenticated Stored Cross-Site…webilia Listdom: AI-powered Business Directory with…
CVE-2026-1948NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-1947NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form…webaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-18027WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated…WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery…
CVE-2026-1630Reflected XSS in WEBCON BPSWEBCON BPS
CVE-2026-15602NEX-Forms <= 9.2.4 - Authenticated (Admin+) SQL Injection via 'additional_params' Parameterwebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-15450NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameterwebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-15142Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID…WebCodingPlace Real Estate Manager Pro
CVE-2026-14894Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)WebRehab Super Forms – Drag & Drop Form Builder
CVE-2026-14631webpack-dev-server vulnerable to denial of service via a malformed Host or Origin headerwebpack-dev-server
CVE-2026-14620webpack-dev-server vulnerable to cross-site request forgery via internal developer endpointswebpack-dev-server
CVE-2026-14352AR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameterwebandprint AR for WooCommerce
CVE-2026-14327AR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' Parameterwebandprint AR for WordPress
CVE-2026-13389WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via…Unknown webtoffee-cookie-consent
CVE-2026-13040NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameterwebaways NEX-Forms – Ultimate Forms Plugin for WordPress
CVE-2026-12872Webinfos <= 1.2 - Unauthenticated Arbitrary File UploadUnknown Webinfos
CVE-2026-1250Court Reservation – Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injectionwebmuehle Court Reservation – Manage Your Court Bookings…

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.