🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-85652 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' S... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-15275 The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter ... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-12739 The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-16777 The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all ... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-15004 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt te... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-14472 The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, a... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-12954 The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_u... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-75961 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params'... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-14323 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-92622 The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all ve... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-90981 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' para... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-13471 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-92554 The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-18442 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-17607 The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortc... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-17586 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta... | MEDIUM | ????? | ????? | NVD | 1 day ago |
| CVE-2026-93494 A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-89058 A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2026-89059 A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared... | HIGH | ????? | ????? | NVD | 1 day ago |
| CVE-2024-38639 An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise th... | MEDIUM | ????? | ????? | NVD | 2 days ago |