Published vulnerability pages

Website Security Risk Index — Page 2

Current vulnerabilities, affected platforms, and fix guidance for website owners and developers.

Browse by topic

Security risk categories

46 categories with published guidance

Memory Corruption

409

Browse published Memory Corruption vulnerabilities, affected products, and practical fix guidance.

Authorization Bypass

373

Browse published Authorization Bypass vulnerabilities, affected products, and practical fix guidance.

WordPress

350

Browse published WordPress vulnerabilities, affected products, and practical fix guidance.

Information Disclosure

320

Browse published Information Disclosure vulnerabilities, affected products, and practical fix guidance.

Remote Code Execution

303

Browse published Remote Code Execution vulnerabilities, affected products, and practical fix guidance.

Cross-site Scripting

260

Browse published Cross-site Scripting vulnerabilities, affected products, and practical fix guidance.

Network Security

253

Browse published Network Security vulnerabilities, affected products, and practical fix guidance.

Input Validation

243

Browse published Input Validation vulnerabilities, affected products, and practical fix guidance.

Web Application

239

Browse published Web Application vulnerabilities, affected products, and practical fix guidance.

Windows

216

Browse published Windows vulnerabilities, affected products, and practical fix guidance.

API Security

215

Browse published API Security vulnerabilities, affected products, and practical fix guidance.

Browser

215

Browse published Browser vulnerabilities, affected products, and practical fix guidance.

Denial of Service

215

Browse published Denial of Service vulnerabilities, affected products, and practical fix guidance.

Microsoft

212

Browse published Microsoft vulnerabilities, affected products, and practical fix guidance.

PHP

199

Browse published PHP vulnerabilities, affected products, and practical fix guidance.

Path Traversal

167

Browse published Path Traversal vulnerabilities, affected products, and practical fix guidance.

Authentication Bypass

118

Browse published Authentication Bypass vulnerabilities, affected products, and practical fix guidance.

Arbitrary File Write

116

Browse published Arbitrary File Write vulnerabilities, affected products, and practical fix guidance.

Privilege Escalation

113

Browse published Privilege Escalation vulnerabilities, affected products, and practical fix guidance.

Linux

94

Browse published Linux vulnerabilities, affected products, and practical fix guidance.

DevOps

81

Browse published DevOps vulnerabilities, affected products, and practical fix guidance.

SQL Injection

72

Browse published SQL Injection vulnerabilities, affected products, and practical fix guidance.

Cryptography

68

Browse published Cryptography vulnerabilities, affected products, and practical fix guidance.

SSRF

61

Browse published SSRF vulnerabilities, affected products, and practical fix guidance.

Python

59

Browse published Python vulnerabilities, affected products, and practical fix guidance.

Java

57

Browse published Java vulnerabilities, affected products, and practical fix guidance.

IDOR

56

Browse published IDOR vulnerabilities, affected products, and practical fix guidance.

WooCommerce

53

Browse published WooCommerce vulnerabilities, affected products, and practical fix guidance.

Unsafe Deserialization

51

Browse published Unsafe Deserialization vulnerabilities, affected products, and practical fix guidance.

File Upload

47

Browse published File Upload vulnerabilities, affected products, and practical fix guidance.

npm

44

Browse published npm vulnerabilities, affected products, and practical fix guidance.

Joomla

41

Browse published Joomla vulnerabilities, affected products, and practical fix guidance.

Supply Chain

39

Browse published Supply Chain vulnerabilities, affected products, and practical fix guidance.

Cloud Security

36

Browse published Cloud Security vulnerabilities, affected products, and practical fix guidance.

CSRF

33

Browse published CSRF vulnerabilities, affected products, and practical fix guidance.

Race Condition

31

Browse published Race Condition vulnerabilities, affected products, and practical fix guidance.

PDF Editor

28

Browse published PDF Editor vulnerabilities, affected products, and practical fix guidance.

Industrial Control

27

Browse published Industrial Control vulnerabilities, affected products, and practical fix guidance.

.NET

23

Browse published .NET vulnerabilities, affected products, and practical fix guidance.

File Deletion

23

Browse published File Deletion vulnerabilities, affected products, and practical fix guidance.

Open Redirect

16

Browse published Open Redirect vulnerabilities, affected products, and practical fix guidance.

Node.js

15

Browse published Node.js vulnerabilities, affected products, and practical fix guidance.

SAML

13

Browse published SAML vulnerabilities, affected products, and practical fix guidance.

Virtualization

13

Browse published Virtualization vulnerabilities, affected products, and practical fix guidance.

Drupal

6

Browse published Drupal vulnerabilities, affected products, and practical fix guidance.

Unix Domain Sockets

5

Browse published Unix Domain Sockets vulnerabilities, affected products, and practical fix guidance.

Published security risks

Showing 37–72 of 2230 published risks.

high

CVE-2026-65511 Manual - Documentation, Knowledge Base & Education WordPress Theme vulnerability

Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVE-2026-65511wordpressxss

Updated Jul 24, 2026

medium

CVE-2026-65514 Appointment Hour Booking vulnerability

Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.

CVE-2026-65514xss

Updated Jul 24, 2026

medium

CVE-2026-65512 WP Activity Log vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.

CVE-2026-65512wordpresscsrf

Updated Jul 24, 2026

high

CVE-2026-65516 PeproDev Ultimate Invoice vulnerability

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVE-2026-65516ssrf

Updated Jul 24, 2026

medium

CVE-2026-65521 WP Social Ninja vulnerability

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

CVE-2026-65521wordpress

Updated Jul 24, 2026

medium

CVE-2026-65518 Accept Donations with PayPal & Stripe vulnerability

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

CVE-2026-65518xss

Updated Jul 24, 2026

medium

CVE-2026-65519 Photo Gallery vulnerability

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

CVE-2026-65519xss

Updated Jul 24, 2026

medium

CVE-2026-65522 Manual - Documentation, Knowledge Base & Education WordPress Theme vulnerability

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVE-2026-65522wordpressxss

Updated Jul 24, 2026

medium

CVE-2026-65525 Civi Framework vulnerability

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

CVE-2026-65525authorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65526 Visualizer vulnerability

Contributor SQL Injection in Visualizer <= 4.0.6 versions.

CVE-2026-65526sql-injection

Updated Jul 24, 2026

medium

CVE-2026-65524 Avada Custom Branding vulnerability

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

CVE-2026-65524authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65527 LIQUID SPEECH BALLOON vulnerability

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

CVE-2026-65527xss

Updated Jul 24, 2026

medium

CVE-2026-65530 TemplateSpare vulnerability

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

CVE-2026-65530authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65529 Graphina vulnerability

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

CVE-2026-65529authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65528 BSK PDF Manager vulnerability

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

CVE-2026-65528xss

Updated Jul 24, 2026

medium

CVE-2026-65531 Qubely vulnerability

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

CVE-2026-65531authorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65532 Persian Woocommerce SMS vulnerability

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

CVE-2026-65532woocommercesql-injection

Updated Jul 24, 2026

medium

CVE-2026-65533 Smart SEO Tool vulnerability

Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions.

CVE-2026-65533xss

Updated Jul 24, 2026

medium

CVE-2026-65534 Custom links in Elementor Image Carousel vulnerability

Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions.

CVE-2026-65534xss

Updated Jul 24, 2026

medium

CVE-2026-65535 TinyMCE Templates vulnerability

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

CVE-2026-65535

Updated Jul 24, 2026

medium

CVE-2026-65537 Cyr to Lat reloaded – transliteration of links and file names vulnerability

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

CVE-2026-65537authorization-bypass

Updated Jul 24, 2026

medium

CVE-2026-65538 Machete vulnerability

Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.

CVE-2026-65538xss

Updated Jul 24, 2026

high

CVE-2026-65539 Kwayy HTML Sitemap vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.

CVE-2026-65539csrf

Updated Jul 24, 2026

high

CVE-2026-65540 Popup for CF7 with Sweet Alert vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.

CVE-2026-65540csrf

Updated Jul 24, 2026

medium

CVE-2026-65550 Tabs vulnerability

Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.

CVE-2026-65550xss

Updated Jul 24, 2026

critical

CVE-2026-65605 siyuan vulnerability

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template without auto-escaping, and EscapeHTML is only applied when HasUnclosedHtmlTag returns true; because balanced self-closing tags such as <img> are skipped by that check, a payload like <img src=x onerror=...> is stored unescaped and later inserted into the page via innerHTML, executing when the database is viewed. Because the desktop renderer runs with nodeIntegration enabled, the injected script can reach require and escalate to arbitrary command execution.

CVE-2026-65605remote-code-executionxss

Updated Jul 24, 2026

critical

CVE-2026-65606 siyuan vulnerability

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed plugin, the application opens a custom tab and inserts the link's icon parameter into the tab header via innerHTML without escaping it (app/src/layout/Tab.ts), allowing injection of an <img onerror=...> element. Because the SiYuan Desktop renderer runs with nodeIntegration:true, the injected JavaScript can access Node's require and call require('child_process').execSync(...), escalating the cross-site scripting into arbitrary operating-system command execution.

CVE-2026-65606remote-code-executionxss

Updated Jul 24, 2026

high

CVE-2026-65607 siyuan vulnerability

SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main export branch, this branch joins the raw, percent-decoded request path with util.TempDir and serves the file without the IsSubPath or IsSensitivePath checks added in the earlier export-disclosure hardening (GHSA-6865-qjcf-286f). An authenticated attacker can send percent-encoded traversal sequences (e.g. /export/temp/%2e%2e/.../etc/passwd, where %2e%2e is decoded to '..') to read arbitrary files outside TempDir, including /etc/passwd, SSH keys (~/.ssh/*), and SiYuan workspace *.db and *.log files, bypassing the sensitive-file protection.

CVE-2026-65607linuxnetwork-securitypath-traversalfile-write

Updated Jul 24, 2026

high

CVE-2026-65608 grav vulnerability

Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registers this handler for every Flex directory, it bypasses the validation added to Blueprint::dynamicData() in 2.0.7 (GHSA-fj2p-qj2f-74v5). Any authenticated user with create or update permission on any Flex-based directory (Flex Users, Flex Pages, Flex Objects, or custom Flex types) can execute arbitrary shell commands on the server.

CVE-2026-65608phpremote-code-execution

Updated Jul 24, 2026

high

CVE-2026-65895 grav vulnerability

Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials enabled.

CVE-2026-65895phpapi-securityauthorization-bypass

Updated Jul 24, 2026

high

CVE-2026-65896 grav vulnerability

Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversal sequences (e.g., 01.home/../../../pwned) to move an entire page directory (content and media) to an arbitrary writable location outside user/pages/, including outside the Grav installation.

CVE-2026-65896phpapi-securitypath-traversal

Updated Jul 24, 2026

high

CVE-2026-65897 grav vulnerability

Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding those permissions.

CVE-2026-65897phpapi-securityprivilege-escalation

Updated Jul 24, 2026

low

CVE-2026-15037 Qt vulnerability

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

CVE-2026-15037

Updated Jul 24, 2026

high

CVE-2026-65906 TeamCity vulnerability

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

CVE-2026-65906devopsremote-code-execution

Updated Jul 24, 2026

critical

CVE-2026-65907 TeamCity vulnerability

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

CVE-2026-65907devopsremote-code-execution

Updated Jul 24, 2026

high

CVE-2026-65908 PyCharm vulnerability

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CVE-2026-65908pythondevopssupply-chainremote-code-execution

Updated Jul 24, 2026