CVE-2026-103062
- EPSS 0.15%
- Veröffentlicht 04.10.2026 07:00:43
- Zuletzt bearbeitet 06.10.2026 15:04:25
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6.
CVE-2026-89412
- EPSS 0.3%
- Veröffentlicht 22.09.2026 06:39:40
- Zuletzt bearbeitet 23.09.2026 19:19:42
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3....
CVE-2026-76053
- EPSS 0.3%
- Veröffentlicht 28.08.2026 02:26:56
- Zuletzt bearbeitet 28.08.2026 20:19:54
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient i...
CVE-2026-19632
- EPSS 0.79%
- Veröffentlicht 26.08.2026 03:39:22
- Zuletzt bearbeitet 26.08.2026 20:17:10
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it p...
CVE-2026-18512
- EPSS 0.24%
- Veröffentlicht 25.08.2026 07:39:51
- Zuletzt bearbeitet 26.08.2026 16:19:05
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation Editor Strings Dropdown in all versions up to, and including, 3....
CVE-2026-78267
- EPSS 0.27%
- Veröffentlicht 24.08.2026 21:31:34
- Zuletzt bearbeitet 27.08.2026 17:20:39
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-66582
- EPSS -
- Veröffentlicht 20.08.2026 12:16:32
- Zuletzt bearbeitet 20.08.2026 17:19:24
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
CVE-2026-75981
- EPSS 0.25%
- Veröffentlicht 19.08.2026 06:37:55
- Zuletzt bearbeitet 20.08.2026 12:48:10
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are u...
CVE-2026-18510
- EPSS 0.24%
- Veröffentlicht 06.08.2026 05:29:25
- Zuletzt bearbeitet 12.08.2026 21:00:52
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient ...
CVE-2026-17505
- EPSS 0.8%
- Veröffentlicht 05.08.2026 06:37:57
- Zuletzt bearbeitet 12.08.2026 21:00:37
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replaci...