Vulnerabilities
- AMP for WP <= 1.1.10 - authenticated (contributor+) stored cross-site scripting v... CVE-2026-0627
2026-01-09
0 views
admin
CVE ID : CVE-2026-0627 Published : Jan. 9, 2026, 8:20 a.m. | 48 minutes ago Description : The AMP for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.1.10. This is due to insufficient sanitization of SVG file content that only removes `
🏷️ Tags
authenticatedcontributorstoredcrossscriptingpublishedminutesdescriptioncve
More from Vulnerabilities
CVE-2026-1981 - Winston AI <= 0.0.3 - missing authorization to authenticated (subscriber+) arbitr...
2026-03-07
0
CVE-2026-1644 - WP Frontend Profile <= 1.3.8 - cross-site request forgery to unauthorized user ac...
2026-03-07
0
CVE-2026-25070 - XikeStor SKS8310-8X PingTestSet Command Injection
2026-03-07
0
CVE-2026-25071 - XikeStor SKS8310-8X switch_config.src Missing Authentication
2026-03-07
0
Trending
1
CVE-2025-61481: Critical Remote Code Execution Vulnerability in MikroTik RouterOS & SwitchOS
2025-10-27 • 189 views
2
CVE-2025-43939: Dell Unity OS Command Injection (High)
2025-10-30 • 148 views
3
Google disputes false claims of massive Gmail data breach
2025-10-30 • 130 views
4
Microsoft: DNS outage impacts Azure and Microsoft 365 services
2025-10-30 • 88 views
5
3.5B Accounts, 1 Critical Flaw: Meta Closes WhatsApp Data-Harvesting
2025-11-25 • 81 views