🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-97342 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-97641 The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and in... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-96647 The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'l... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-96871 The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and in... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-96566 The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Fie... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-97336 The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-96567 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and incl... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-96578 The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versi... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-94432 The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Re... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-95670 The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to,... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93756 The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Faceboo... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-95817 The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-93880 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dyn... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-12951 The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/com... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-103426 The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-102772 The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code field id> (e.g. kl_code, kl_post_code)... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-102002 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposur... | LOW | ????? | ????? | NVD | 5 days ago |
| CVE-2026-100182 The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-100107 The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up t... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-85714 R Summary An authenticated admin can upload a crafted `.sql` file to `POST /api/v1/database/import-database` that executes arbitrary OS commands on the ... | CRITICAL | ????? | ????? | NVD | 5 days ago |