Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54155
Total
4297
Critical
16098
High
15777
Medium
CVE ID Severity Score Description Published
CVE-2026-97644 HIGH 8.8 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, … Oct 03, 2026
CVE-2026-92977 HIGH 7.2 The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, … Oct 03, 2026
CVE-2026-92826 MEDIUM 6.1 The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 … Oct 03, 2026
CVE-2026-92727 MEDIUM 6.4 The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site … Oct 03, 2026
CVE-2026-92551 MEDIUM 6.1 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site … Oct 03, 2026
CVE-2026-92538 MEDIUM 6.1 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' … Oct 03, 2026
CVE-2026-92536 HIGH 8.8 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information … Oct 03, 2026
CVE-2026-96270 HIGH 7.2 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Oct 03, 2026
CVE-2026-95865 MEDIUM 6.5 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all … Oct 03, 2026
CVE-2026-94539 MEDIUM 6.5 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter … Oct 03, 2026
CVE-2026-94378 MEDIUM 6.4 The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter … Oct 03, 2026
CVE-2026-93428 HIGH 7.5 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all … Oct 03, 2026
CVE-2026-92243 MEDIUM 6.1 The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, … Oct 03, 2026
CVE-2026-100180 MEDIUM 5.4 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Oct 03, 2026
CVE-2026-105090 UNKNOWN — Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A … Oct 03, 2026
CVE-2026-105083 LOW 3.9 ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A … Oct 03, 2026
CVE-2026-79113 UNKNOWN — OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow. Oct 03, 2026
CVE-2026-105080 CRITICAL 9.9 In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in … Oct 03, 2026
CVE-2026-105030 MEDIUM 5.3 Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers … Oct 03, 2026
CVE-2026-105029 MEDIUM 4.3 UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' … Oct 03, 2026
CVE-2026-104479 MEDIUM 5.4 Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is … Oct 03, 2026
CVE-2026-104478 HIGH 7.1 Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download … Oct 03, 2026
CVE-2026-104477 MEDIUM 6.1 Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed … Oct 03, 2026
CVE-2026-104476 MEDIUM 5.9 Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers … Oct 03, 2026
CVE-2026-104475 MEDIUM 5.4 IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can … Oct 03, 2026