| CVE/PSC | Application | Date | Affected versions | Description |
|---|---|---|---|---|
| Actual on: Jul 29, 2026, 15:07:20 | ||||
|
vulnerable
|
Jul 29, 2026, 20:07:06 |
Min -
Max 1.36.3.1
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3. | |
|
vulnerable
|
Jul 29, 2026, 19:07:57 |
Min -
Max 3.8.8.1
|
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
|
vulnerable
|
Jul 29, 2026, 19:07:57 |
Min -
Max 3.8.8.1
|
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Because the payload is stored in term meta rather than post content, the WordPress unf... | |
|
vulnerable
|
Jul 29, 2026, 19:07:57 |
Min -
Max 3.8.8.1
|
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
|
Tickera – WordPress Event Ticketing
vulnerable
|
Jul 29, 2026, 19:07:42 |
Min -
Max 3.6.0.2
|
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive informatio... | |
|
Tickera – WordPress Event Ticketing
vulnerable
|
Jul 29, 2026, 19:07:42 |
Min -
Max 3.6.0.2
|
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from ... | |
|
MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution
vulnerable
|
Jul 29, 2026, 19:07:41 |
Min -
Max 2.1.50
|
Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | |
|
vulnerable
|
Jul 29, 2026, 19:07:35 |
Min -
Max 6.1.0
|
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | |
|
BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support
vulnerable
|
Jul 29, 2026, 19:07:34 |
Min -
Max 4.7.0
|
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | |
|
vulnerable
|
Jul 29, 2026, 19:07:28 |
Min -
Max 1.16.3
|
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. | |