Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54367
Total
4306
Critical
16164
High
15850
Medium
CVE ID Severity Score Description Published
CVE-2026-96525 LOW 2.7 The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete … Sep 26, 2026
CVE-2026-96524 HIGH 8.8 The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an … Sep 26, 2026
CVE-2026-92411 MEDIUM 6.8 The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it … Sep 26, 2026
CVE-2026-89237 MEDIUM 6.8 The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers … Sep 26, 2026
CVE-2026-85081 HIGH 7.5 The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin … Sep 26, 2026
CVE-2026-84097 MEDIUM 6.5 The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using … Sep 26, 2026
CVE-2026-84096 HIGH 8.0 The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce … Sep 26, 2026
CVE-2026-84095 HIGH 8.0 The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated … Sep 26, 2026
CVE-2026-19708 MEDIUM 5.9 The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under … Sep 26, 2026
CVE-2026-18143 CRITICAL 9.8 The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the … Sep 26, 2026
CVE-2026-16591 HIGH 7.2 The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page … Sep 26, 2026
CVE-2026-11871 MEDIUM 5.3 The Team Members WordPress plugin through 9.2 does not perform any authorization or visibility check in an unauthenticated AJAX action that returns full team member … Sep 26, 2026
CVE-2026-15273 MEDIUM 6.4 The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. … Sep 26, 2026
CVE-2026-100599 HIGH 8.8 OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The googlemeet.chrome command accepts caller-supplied audio command … Sep 26, 2026
CVE-2026-100598 HIGH 7.1 OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction intended to resolve a structured approval request could instead … Sep 26, 2026
CVE-2026-100597 HIGH 7.8 OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell local mirror filesystem mutation operations. The remove, mkdir, and … Sep 26, 2026
CVE-2026-100596 HIGH 8.8 OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp set and /mcp unset commands. Attackers can persist arbitrary … Sep 26, 2026
CVE-2026-100595 MEDIUM 6.5 OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows non-owner channel senders to access owner-only host diagnostic bundles. … Sep 26, 2026
CVE-2026-100594 MEDIUM 6.5 OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allows non-owner senders to request and receive owner-only trajectory bundles. Attackers … Sep 26, 2026
CVE-2026-100593 MEDIUM 5.4 OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/activation` policy changes in group channels. An authorized non-owner channel … Sep 26, 2026
CVE-2026-100592 MEDIUM 6.3 OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutations omit owner permission checks. An authorized … Sep 26, 2026
CVE-2026-100591 MEDIUM 6.3 OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could omit owner checks. An authorized non-owner external-channel sender … Sep 26, 2026
CVE-2026-100590 MEDIUM 4.3 OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner external-channel senders to persist Gateway voice configuration. Attackers with … Sep 26, 2026
CVE-2026-100589 HIGH 8.3 OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false … Sep 26, 2026
CVE-2026-100588 HIGH 8.3 OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although … Sep 26, 2026