CVE-2026-87920
- EPSS 0.24%
- Veröffentlicht 02.10.2026 09:25:56
- Zuletzt bearbeitet 03.10.2026 16:16:40
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This mak...
CVE-2026-78438
- EPSS 0.29%
- Veröffentlicht 05.09.2026 06:37:57
- Zuletzt bearbeitet 08.09.2026 13:12:58
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This mak...
CVE-2026-18109
- EPSS 0.27%
- Veröffentlicht 14.08.2026 02:25:46
- Zuletzt bearbeitet 14.08.2026 19:09:56
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthent...
CVE-2026-66695
- EPSS 0.27%
- Veröffentlicht 06.08.2026 14:28:03
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-9282
- EPSS 2.77%
- Veröffentlicht 11.07.2026 06:50:33
- Zuletzt bearbeitet 14.07.2026 15:17:11
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on th...
- EPSS 0.32%
- Veröffentlicht 02.07.2026 11:15:25
- Zuletzt bearbeitet 02.07.2026 15:17:09
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
CVE-2026-39595
- EPSS 0.21%
- Veröffentlicht 17.06.2026 09:50:53
- Zuletzt bearbeitet 17.06.2026 09:50:53
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
CVE-2026-5032
- EPSS 3.06%
- Veröffentlicht 02.04.2026 07:39:36
- Zuletzt bearbeitet 27.04.2026 19:04:22
The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header co...
- EPSS 0.3%
- Veröffentlicht 05.03.2026 06:16:27
- Zuletzt bearbeitet 22.04.2026 21:26:58
Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1.
CVE-2024-12365
- EPSS 1.8%
- Veröffentlicht 14.01.2025 07:15:26
- Zuletzt bearbeitet 16.01.2025 21:31:22
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers,...