Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54704
Total
4321
Critical
16261
High
15994
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93897 | MEDIUM | 6.4 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., … | Sep 25, 2026 |
| CVE-2026-93477 | UNKNOWN | — | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the … | Sep 25, 2026 |
| CVE-2026-93399 | CRITICAL | 9.1 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and … | Sep 25, 2026 |
| CVE-2026-93303 | HIGH | 7.2 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich … | Sep 25, 2026 |
| CVE-2026-92829 | MEDIUM | 4.3 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This … | Sep 25, 2026 |
| CVE-2026-92799 | MEDIUM | 5.3 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up … | Sep 25, 2026 |
| CVE-2026-92746 | MEDIUM | 6.4 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute … | Sep 25, 2026 |
| CVE-2026-92212 | MEDIUM | 6.1 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field … | Sep 25, 2026 |
| CVE-2026-89055 | CRITICAL | 9.1 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to … | Sep 25, 2026 |
| CVE-2026-84281 | HIGH | 7.2 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, … | Sep 25, 2026 |
| CVE-2026-84279 | HIGH | 7.2 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 … | Sep 25, 2026 |
| CVE-2026-83591 | HIGH | 7.2 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all … | Sep 25, 2026 |
| CVE-2026-78397 | MEDIUM | 4.0 | The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its … | Sep 25, 2026 |
| CVE-2026-78394 | MEDIUM | 4.1 | The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the … | Sep 25, 2026 |
| CVE-2026-78393 | MEDIUM | 6.1 | The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its … | Sep 25, 2026 |
| CVE-2026-75553 | LOW | 2.4 | Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from … | Sep 25, 2026 |
| CVE-2026-62062 | HIGH | 8.8 | Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1. | Sep 25, 2026 |
| CVE-2026-19775 | MEDIUM | 4.3 | The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, … | Sep 25, 2026 |
| CVE-2026-14281 | CRITICAL | 9.8 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up … | Sep 25, 2026 |
| CVE-2026-97721 | LOW | 2.7 | A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserAdminController.java of the component exportExcel/exportData. … | Sep 25, 2026 |
| CVE-2026-97818 | HIGH | 8.6 | phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. | Sep 25, 2026 |
| CVE-2026-97764 | LOW | 3.7 | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of … | Sep 25, 2026 |
| CVE-2026-97737 | HIGH | 7.4 | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. | Sep 25, 2026 |
| CVE-2026-97736 | MEDIUM | 5.4 | tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression. | Sep 25, 2026 |
| CVE-2026-97735 | HIGH | 8.0 | ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders. | Sep 25, 2026 |