Published vulnerability pages

Website Security Risk Index — Page 31

Current vulnerabilities, affected platforms, and fix guidance for website owners and developers.

Browse by topic

Security risk categories

46 categories with published guidance

Memory Corruption

409

Browse published Memory Corruption vulnerabilities, affected products, and practical fix guidance.

Authorization Bypass

373

Browse published Authorization Bypass vulnerabilities, affected products, and practical fix guidance.

WordPress

350

Browse published WordPress vulnerabilities, affected products, and practical fix guidance.

Information Disclosure

320

Browse published Information Disclosure vulnerabilities, affected products, and practical fix guidance.

Remote Code Execution

303

Browse published Remote Code Execution vulnerabilities, affected products, and practical fix guidance.

Cross-site Scripting

260

Browse published Cross-site Scripting vulnerabilities, affected products, and practical fix guidance.

Network Security

253

Browse published Network Security vulnerabilities, affected products, and practical fix guidance.

Input Validation

243

Browse published Input Validation vulnerabilities, affected products, and practical fix guidance.

Web Application

239

Browse published Web Application vulnerabilities, affected products, and practical fix guidance.

Windows

216

Browse published Windows vulnerabilities, affected products, and practical fix guidance.

API Security

215

Browse published API Security vulnerabilities, affected products, and practical fix guidance.

Browser

215

Browse published Browser vulnerabilities, affected products, and practical fix guidance.

Denial of Service

215

Browse published Denial of Service vulnerabilities, affected products, and practical fix guidance.

Microsoft

212

Browse published Microsoft vulnerabilities, affected products, and practical fix guidance.

PHP

199

Browse published PHP vulnerabilities, affected products, and practical fix guidance.

Path Traversal

167

Browse published Path Traversal vulnerabilities, affected products, and practical fix guidance.

Authentication Bypass

118

Browse published Authentication Bypass vulnerabilities, affected products, and practical fix guidance.

Arbitrary File Write

116

Browse published Arbitrary File Write vulnerabilities, affected products, and practical fix guidance.

Privilege Escalation

113

Browse published Privilege Escalation vulnerabilities, affected products, and practical fix guidance.

Linux

94

Browse published Linux vulnerabilities, affected products, and practical fix guidance.

DevOps

81

Browse published DevOps vulnerabilities, affected products, and practical fix guidance.

SQL Injection

72

Browse published SQL Injection vulnerabilities, affected products, and practical fix guidance.

Cryptography

68

Browse published Cryptography vulnerabilities, affected products, and practical fix guidance.

SSRF

61

Browse published SSRF vulnerabilities, affected products, and practical fix guidance.

Python

59

Browse published Python vulnerabilities, affected products, and practical fix guidance.

Java

57

Browse published Java vulnerabilities, affected products, and practical fix guidance.

IDOR

56

Browse published IDOR vulnerabilities, affected products, and practical fix guidance.

WooCommerce

53

Browse published WooCommerce vulnerabilities, affected products, and practical fix guidance.

Unsafe Deserialization

51

Browse published Unsafe Deserialization vulnerabilities, affected products, and practical fix guidance.

File Upload

47

Browse published File Upload vulnerabilities, affected products, and practical fix guidance.

npm

44

Browse published npm vulnerabilities, affected products, and practical fix guidance.

Joomla

41

Browse published Joomla vulnerabilities, affected products, and practical fix guidance.

Supply Chain

39

Browse published Supply Chain vulnerabilities, affected products, and practical fix guidance.

Cloud Security

36

Browse published Cloud Security vulnerabilities, affected products, and practical fix guidance.

CSRF

33

Browse published CSRF vulnerabilities, affected products, and practical fix guidance.

Race Condition

31

Browse published Race Condition vulnerabilities, affected products, and practical fix guidance.

PDF Editor

28

Browse published PDF Editor vulnerabilities, affected products, and practical fix guidance.

Industrial Control

27

Browse published Industrial Control vulnerabilities, affected products, and practical fix guidance.

.NET

23

Browse published .NET vulnerabilities, affected products, and practical fix guidance.

File Deletion

23

Browse published File Deletion vulnerabilities, affected products, and practical fix guidance.

Open Redirect

16

Browse published Open Redirect vulnerabilities, affected products, and practical fix guidance.

Node.js

15

Browse published Node.js vulnerabilities, affected products, and practical fix guidance.

SAML

13

Browse published SAML vulnerabilities, affected products, and practical fix guidance.

Virtualization

13

Browse published Virtualization vulnerabilities, affected products, and practical fix guidance.

Drupal

6

Browse published Drupal vulnerabilities, affected products, and practical fix guidance.

Unix Domain Sockets

5

Browse published Unix Domain Sockets vulnerabilities, affected products, and practical fix guidance.

Published security risks

Showing 1081–1116 of 2230 published risks.

highEPSS 0.007

CVE-2026-45305 in Symfony YAML

Symfony YAML can hang on crafted YAML because of slow regex backtracking.

CVE-2026-45305phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45071 in Symfony DomCrawler

Symfony DomCrawler can read local files when it parses attacker-controlled XML content.

CVE-2026-45071phpweb-applicationinput-validationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-47212 in Symfony Twilio Notifier

Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.

CVE-2026-47212phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47984 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47984phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47988 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47988phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.196

CVE-2026-47992 in Adobe Commerce

Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.

CVE-2026-47992phpweb-applicationremote-code-executionsql-injection

Updated Jul 15, 2026

highEPSS 0.009

CVE-2026-47994 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47994phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-47995 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47995phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.185

CVE-2026-47996 in Adobe Commerce

Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.

CVE-2026-47996phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47997 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47997phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47998 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47998phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.115

CVE-2026-47999 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.

CVE-2026-47999phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-48000 in Adobe Commerce

Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.

CVE-2026-48000phpweb-applicationopen-redirect

Updated Jul 15, 2026

lowEPSS 0.006

CVE-2026-48001 in Adobe Commerce

Adobe Commerce can expose limited sensitive information under certain conditions.

CVE-2026-48001phpweb-applicationinformation-disclosure

Updated Jul 15, 2026

criticalEPSS 0.283

CVE-2026-48356 in Adobe Commerce

Adobe Commerce allows dangerous file upload in a way that can lead to code execution after user interaction.

CVE-2026-48356phpweb-applicationremote-code-executionfile-upload

Updated Jul 15, 2026

criticalEPSS 0.009

CVE-2026-48358 in Adobe Commerce

Adobe Commerce has an output escaping issue that can lead to code execution without user interaction.

CVE-2026-48358phpweb-applicationremote-code-executioninput-validation

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-48371 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.

CVE-2026-48371phpweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-48489 in Symfony Security HTTP

Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.

CVE-2026-48489phpweb-applicationauthentication-bypassauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-48747 in Symfony Mailomat Mailer

Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.

CVE-2026-48747phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48760 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.

CVE-2026-48760phpweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48761 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.

CVE-2026-48761phpweb-applicationinput-validationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48784 in Symfony Routing

Symfony Routing can generate a URL that collapses to a different path when dot segments are normalized.

CVE-2026-48784phpweb-applicationinput-validationopen-redirect

Updated Jul 15, 2026

criticalEPSS 0.003

Grand Photography WordPress <= 5.7.8 - Unauthenticated PHP Object Injection

Grand Photography WordPress has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.

CVE-2026-57770wordpressphpfile-writefile-deletion

Updated Jul 15, 2026

highEPSS 0.002

Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting

Unlimited Elements For Elementor has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57718wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57711wordpressbrowserxss

Updated Jul 15, 2026

medium

Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting

Breakdance has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57735wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57708wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting

Document Gallery has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57695wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting

Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57691wordpressbrowsernetwork-securityxss

Updated Jul 15, 2026

highEPSS 0.002

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting

NEX-Forms – Ultimate Forms Plugin for WordPress has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57668wordpressbrowserxss

Updated Jul 15, 2026

mediumEPSS 0.002

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.

CVE-2026-57812wordpressauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization

Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.

CVE-2026-59523wordpressauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting

Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57706wordpresswoocommercebrowserxss

Updated Jul 15, 2026

criticalEPSS 0.003

Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.8.2 - Authenticated (Subscriber+) PHP Object Injection

Directorist: AI-Powered Business Directory, Listings & Classified Ads has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.

CVE-2026-59518wordpressphpfile-writefile-deletion

Updated Jul 15, 2026

highEPSS 0.001

FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting

FunnelKit – Funnel Builder for WooCommerce Checkout has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57816wordpresswoocommercebrowserxss

Updated Jul 15, 2026

criticalEPSS 0.003

AI Copilot – Content Generator <= 1.5.4 - Unauthenticated SQL Injection

AI Copilot – Content Generator has a SQL injection issue. An attacker with the needed access can change a request and may read database data.

CVE-2026-59515wordpresssql-injectioninformation-disclosure

Updated Jul 15, 2026