Known Vulnerabilities for User Import Export by Igniterealtime

Listed below are 1 of the newest known vulnerabilities associated with "User Import Export" by "Igniterealtime".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-58174 json Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the... Not Provided 2026-06-30 2026-07-14
CVE-2026-53447 json Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses cal... Not Provided 2026-07-15 2026-07-16
CVE-2026-15026 json The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all version... Not Provided 2026-07-10 2026-07-10
CVE-2026-13353 json The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote ... Not Provided 2026-07-11 2026-07-13
CVE-2026-7816 json OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolated di... Not Provided 2026-05-11 2026-05-26
CVE-2026-7641 json The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to an... Not Provided 2026-05-02 2026-05-04
CVE-2026-5335 json The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making i... Not Provided 2026-05-04 2026-05-04
CVE-2025-9902 json Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trade Co.... Not Provided 2025-10-13 2026-06-05
CVE-2017-2815 json An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web... 8.1 - HIGH 2018-05-15 2022-04-19

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report