CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78362
9.8 CRITICAL

The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be …

Sep 5, 2026
CVE-2026-78150
2.7 LOW

The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users …

Sep 5, 2026
CVE-2026-78149
5.3 MEDIUM

The Smart Post WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through …

Sep 5, 2026
CVE-2026-77830
7.2 HIGH

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up …

Sep 5, 2026
CVE-2026-77826
8.8 HIGH

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, …

Sep 5, 2026
CVE-2026-4361
5.0 MEDIUM

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` …

Sep 5, 2026
CVE-2026-3853
6.4 MEDIUM

The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, …

Sep 5, 2026
CVE-2026-19887
8.8 HIGH

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input …

Sep 5, 2026
CVE-2026-19861
4.7 MEDIUM

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in …

Sep 5, 2026
CVE-2026-19858
7.5 HIGH

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated …

Sep 5, 2026
CVE-2026-19769
7.2 HIGH

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' …

Sep 5, 2026
CVE-2026-18843
6.1 MEDIUM

The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and …

Sep 5, 2026
CVE-2026-18406
7.2 HIGH

The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field …

Sep 5, 2026
CVE-2026-16649
7.2 HIGH

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 …

Sep 5, 2026
CVE-2026-15984
7.2 HIGH

The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to …

Sep 5, 2026
CVE-2026-15247
5.4 MEDIUM

The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its …

Sep 5, 2026
CVE-2026-14975
6.5 MEDIUM

The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This …

Sep 5, 2026
CVE-2025-15694
3.5 LOW

The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, …

Sep 5, 2026
CVE-2025-15693
2.7 LOW

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the …

Sep 5, 2026
CVE-2026-8625
6.4 MEDIUM

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom …

Sep 5, 2026
CVE-2026-8623
6.4 MEDIUM

The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class …

Sep 5, 2026
CVE-2026-86145
8.2 HIGH

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check …

Sep 5, 2026
CVE-2026-83628
4.3 MEDIUM

The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due …

Sep 5, 2026
CVE-2026-83627
9.8 CRITICAL

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and …

Sep 5, 2026
CVE-2026-77263
7.2 HIGH

The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content …

Sep 5, 2026
CVE-2026-77233
7.2 HIGH

The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content …

Sep 5, 2026
CVE-2026-18404
6.4 MEDIUM

The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box …

Sep 5, 2026
CVE-2026-13447
9.8 CRITICAL

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to …

Sep 5, 2026
CVE-2025-14945
5.4 MEDIUM

The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions …

Sep 5, 2026
CVE-2026-86144
5.6 MEDIUM

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without …

Sep 5, 2026
CVE-2026-86143
6.9 MEDIUM

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check …

Sep 5, 2026
CVE-2026-86142
6.9 MEDIUM

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

Sep 5, 2026
CVE-2026-86141
2.9 LOW

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after …

Sep 5, 2026
CVE-2026-86140
8.0 HIGH

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

Sep 5, 2026
CVE-2026-86139
6.9 MEDIUM

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

Sep 5, 2026
CVE-2026-86138
6.9 MEDIUM

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

Sep 5, 2026
CVE-2026-86137
2.9 LOW

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

Sep 5, 2026
CVE-2026-86100
6.4 MEDIUM

Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can …

Sep 5, 2026
CVE-2026-52777

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This …

Sep 5, 2026
CVE-2026-52775
8.8 HIGH

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() …

Sep 5, 2026
CVE-2026-52774
6.1 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using …

Sep 5, 2026
CVE-2026-52773
6.1 MEDIUM

YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a …

Sep 5, 2026
CVE-2026-52772
5.5 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and …

Sep 5, 2026
CVE-2026-52771
8.3 HIGH

YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into …

Sep 5, 2026
CVE-2026-52770
7.5 HIGH

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric …

Sep 5, 2026
CVE-2026-52769
8.3 HIGH

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - …

Sep 5, 2026
CVE-2026-52767
8.2 HIGH

YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose …

Sep 5, 2026
CVE-2026-52766
9.1 CRITICAL

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes …

Sep 5, 2026
CVE-2026-52763
6.5 MEDIUM

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. …

Sep 5, 2026
CVE-2026-52762

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic …

Sep 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.