Advanced Threat Data Export
Filter and download the raw CVE repository (CSV/JSON) for SIEM integration and internal reporting.
Data export is locked. Upgrade your package to enable filtering and downloading.
🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2024-13784 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, ... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-2497 The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in al... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-2357 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-18347 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17608 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17604 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to,... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-17087 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-13424 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-12998 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference i... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-10734 The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and includin... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-9767 The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' P... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-2283 The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including,... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19728 The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploade... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19726 The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contribut... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19725 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19717 The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19714 The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated ... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19712 The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instruc... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19711 The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, a... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-19613 The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom fi... | MEDIUM | ????? | ????? | NVD | 5 days ago |