Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54499
Total
4309
Critical
16193
High
15930
Medium
CVE ID Severity Score Description Published
CVE-2026-93656 MEDIUM 6.4 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Sep 25, 2026
CVE-2026-93654 HIGH 7.2 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter in all versions up to, … Sep 25, 2026
CVE-2026-92713 HIGH 8.1 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … Sep 25, 2026
CVE-2026-92609 CRITICAL 9.8 Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained … Sep 25, 2026
CVE-2026-92608 HIGH 7.5 Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties … Sep 25, 2026
CVE-2026-89426 HIGH 8.8 The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, … Sep 25, 2026
CVE-2026-89406 HIGH 7.5 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of private gallery contents in versions up … Sep 25, 2026
CVE-2026-88996 MEDIUM 6.1 The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected … Sep 25, 2026
CVE-2026-84280 HIGH 7.2 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, … Sep 25, 2026
CVE-2026-19804 HIGH 8.8 The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution … Sep 25, 2026
CVE-2026-17602 MEDIUM 4.9 The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … Sep 25, 2026
CVE-2026-17577 MEDIUM 6.1 The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42. … Sep 25, 2026
CVE-2026-13456 HIGH 7.5 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … Sep 25, 2026
CVE-2026-13179 MEDIUM 6.4 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up … Sep 25, 2026
CVE-2026-12037 MEDIUM 5.5 The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the … Sep 25, 2026
CVE-2026-97846 MEDIUM 6.8 Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by … Sep 25, 2026
CVE-2026-96766 MEDIUM 6.4 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in … Sep 25, 2026
CVE-2026-96039 HIGH 7.2 The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due … Sep 25, 2026
CVE-2026-94376 MEDIUM 6.4 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via … Sep 25, 2026
CVE-2026-93899 MEDIUM 6.5 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' … Sep 25, 2026
CVE-2026-93897 MEDIUM 6.4 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., … Sep 25, 2026
CVE-2026-93477 UNKNOWN — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the … Sep 25, 2026
CVE-2026-93399 CRITICAL 9.1 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and … Sep 25, 2026
CVE-2026-93303 HIGH 7.2 The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich … Sep 25, 2026
CVE-2026-92829 MEDIUM 4.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This … Sep 25, 2026