CVE-2026-19857: Improper Neutralization of Special Elements in Output Used by a Downstream Component
The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, ...
CVE-2026-65669: Improper Neutralization of Special Elements in Output Used by a Downstream Component
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. With curated ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results