Published vulnerability pages
Website Security Risk Index — Page 31
Current vulnerabilities, affected platforms, and fix guidance for website owners and developers.
Browse by topic
Security risk categories
46 categories with published guidance
Memory Corruption
409Browse published Memory Corruption vulnerabilities, affected products, and practical fix guidance.
Authorization Bypass
373Browse published Authorization Bypass vulnerabilities, affected products, and practical fix guidance.
WordPress
350Browse published WordPress vulnerabilities, affected products, and practical fix guidance.
Information Disclosure
320Browse published Information Disclosure vulnerabilities, affected products, and practical fix guidance.
Remote Code Execution
303Browse published Remote Code Execution vulnerabilities, affected products, and practical fix guidance.
Cross-site Scripting
260Browse published Cross-site Scripting vulnerabilities, affected products, and practical fix guidance.
Network Security
253Browse published Network Security vulnerabilities, affected products, and practical fix guidance.
Input Validation
243Browse published Input Validation vulnerabilities, affected products, and practical fix guidance.
Web Application
239Browse published Web Application vulnerabilities, affected products, and practical fix guidance.
Windows
216Browse published Windows vulnerabilities, affected products, and practical fix guidance.
API Security
215Browse published API Security vulnerabilities, affected products, and practical fix guidance.
Browser
215Browse published Browser vulnerabilities, affected products, and practical fix guidance.
Denial of Service
215Browse published Denial of Service vulnerabilities, affected products, and practical fix guidance.
Microsoft
212Browse published Microsoft vulnerabilities, affected products, and practical fix guidance.
PHP
199Browse published PHP vulnerabilities, affected products, and practical fix guidance.
Path Traversal
167Browse published Path Traversal vulnerabilities, affected products, and practical fix guidance.
Authentication Bypass
118Browse published Authentication Bypass vulnerabilities, affected products, and practical fix guidance.
Arbitrary File Write
116Browse published Arbitrary File Write vulnerabilities, affected products, and practical fix guidance.
Privilege Escalation
113Browse published Privilege Escalation vulnerabilities, affected products, and practical fix guidance.
Linux
94Browse published Linux vulnerabilities, affected products, and practical fix guidance.
DevOps
81Browse published DevOps vulnerabilities, affected products, and practical fix guidance.
SQL Injection
72Browse published SQL Injection vulnerabilities, affected products, and practical fix guidance.
Cryptography
68Browse published Cryptography vulnerabilities, affected products, and practical fix guidance.
SSRF
61Browse published SSRF vulnerabilities, affected products, and practical fix guidance.
Python
59Browse published Python vulnerabilities, affected products, and practical fix guidance.
Java
57Browse published Java vulnerabilities, affected products, and practical fix guidance.
IDOR
56Browse published IDOR vulnerabilities, affected products, and practical fix guidance.
WooCommerce
53Browse published WooCommerce vulnerabilities, affected products, and practical fix guidance.
Unsafe Deserialization
51Browse published Unsafe Deserialization vulnerabilities, affected products, and practical fix guidance.
File Upload
47Browse published File Upload vulnerabilities, affected products, and practical fix guidance.
npm
44Browse published npm vulnerabilities, affected products, and practical fix guidance.
Joomla
41Browse published Joomla vulnerabilities, affected products, and practical fix guidance.
Supply Chain
39Browse published Supply Chain vulnerabilities, affected products, and practical fix guidance.
Cloud Security
36Browse published Cloud Security vulnerabilities, affected products, and practical fix guidance.
CSRF
33Browse published CSRF vulnerabilities, affected products, and practical fix guidance.
Race Condition
31Browse published Race Condition vulnerabilities, affected products, and practical fix guidance.
PDF Editor
28Browse published PDF Editor vulnerabilities, affected products, and practical fix guidance.
Industrial Control
27Browse published Industrial Control vulnerabilities, affected products, and practical fix guidance.
.NET
23Browse published .NET vulnerabilities, affected products, and practical fix guidance.
File Deletion
23Browse published File Deletion vulnerabilities, affected products, and practical fix guidance.
Open Redirect
16Browse published Open Redirect vulnerabilities, affected products, and practical fix guidance.
Node.js
15Browse published Node.js vulnerabilities, affected products, and practical fix guidance.
SAML
13Browse published SAML vulnerabilities, affected products, and practical fix guidance.
Virtualization
13Browse published Virtualization vulnerabilities, affected products, and practical fix guidance.
Drupal
6Browse published Drupal vulnerabilities, affected products, and practical fix guidance.
Unix Domain Sockets
5Browse published Unix Domain Sockets vulnerabilities, affected products, and practical fix guidance.
Published security risks
Showing 1081–1116 of 2230 published risks.
CVE-2026-45305 in Symfony YAML
Symfony YAML can hang on crafted YAML because of slow regex backtracking.
Updated Jul 15, 2026
CVE-2026-45071 in Symfony DomCrawler
Symfony DomCrawler can read local files when it parses attacker-controlled XML content.
Updated Jul 15, 2026
CVE-2026-47212 in Symfony Twilio Notifier
Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.
Updated Jul 15, 2026
CVE-2026-47984 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47988 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47992 in Adobe Commerce
Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.
Updated Jul 15, 2026
CVE-2026-47994 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47995 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47996 in Adobe Commerce
Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47997 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47998 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47999 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48000 in Adobe Commerce
Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.
Updated Jul 15, 2026
CVE-2026-48001 in Adobe Commerce
Adobe Commerce can expose limited sensitive information under certain conditions.
Updated Jul 15, 2026
CVE-2026-48356 in Adobe Commerce
Adobe Commerce allows dangerous file upload in a way that can lead to code execution after user interaction.
Updated Jul 15, 2026
CVE-2026-48358 in Adobe Commerce
Adobe Commerce has an output escaping issue that can lead to code execution without user interaction.
Updated Jul 15, 2026
CVE-2026-48371 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48489 in Symfony Security HTTP
Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.
Updated Jul 15, 2026
CVE-2026-48747 in Symfony Mailomat Mailer
Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.
Updated Jul 15, 2026
CVE-2026-48760 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.
Updated Jul 15, 2026
CVE-2026-48761 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.
Updated Jul 15, 2026
CVE-2026-48784 in Symfony Routing
Symfony Routing can generate a URL that collapses to a different path when dot segments are normalized.
Updated Jul 15, 2026
Grand Photography WordPress <= 5.7.8 - Unauthenticated PHP Object Injection
Grand Photography WordPress has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.
Updated Jul 15, 2026
Unlimited Elements For Elementor <= 2.0.12 - Unauthenticated Stored Cross-Site Scripting
Unlimited Elements For Elementor has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting
Breakdance has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
Database for Contact Form 7, WPforms, Elementor forms has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting
Document Gallery has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Anti-Malware Security and Brute-Force Firewall <= 4.23.89 - Unauthenticated Stored Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting
NEX-Forms – Ultimate Forms Plugin for WordPress has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.12.4 - Missing Authorization
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.
Updated Jul 15, 2026
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.11 - Missing Authorization
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin misses an authorization check. A logged-in user can do an action they should not be allowed to do.
Updated Jul 15, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.8.2 - Authenticated (Subscriber+) PHP Object Injection
Directorist: AI-Powered Business Directory, Listings & Classified Ads has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.
Updated Jul 15, 2026
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting
FunnelKit – Funnel Builder for WooCommerce Checkout has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.
Updated Jul 15, 2026
AI Copilot – Content Generator <= 1.5.4 - Unauthenticated SQL Injection
AI Copilot – Content Generator has a SQL injection issue. An attacker with the needed access can change a request and may read database data.
Updated Jul 15, 2026
