Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54704
Total
4321
Critical
16261
High
15994
Medium
CVE ID Severity Score Description Published
CVE-2026-93897 MEDIUM 6.4 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., … Sep 25, 2026
CVE-2026-93477 UNKNOWN — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a user to set the value of a private action argument on the … Sep 25, 2026
CVE-2026-93399 CRITICAL 9.1 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and … Sep 25, 2026
CVE-2026-93303 HIGH 7.2 The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich … Sep 25, 2026
CVE-2026-92829 MEDIUM 4.3 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This … Sep 25, 2026
CVE-2026-92799 MEDIUM 5.3 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up … Sep 25, 2026
CVE-2026-92746 MEDIUM 6.4 The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute … Sep 25, 2026
CVE-2026-92212 MEDIUM 6.1 The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field … Sep 25, 2026
CVE-2026-89055 CRITICAL 9.1 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to … Sep 25, 2026
CVE-2026-84281 HIGH 7.2 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, … Sep 25, 2026
CVE-2026-84279 HIGH 7.2 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 … Sep 25, 2026
CVE-2026-83591 HIGH 7.2 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all … Sep 25, 2026
CVE-2026-78397 MEDIUM 4.0 The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its … Sep 25, 2026
CVE-2026-78394 MEDIUM 4.1 The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the … Sep 25, 2026
CVE-2026-78393 MEDIUM 6.1 The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its … Sep 25, 2026
CVE-2026-75553 LOW 2.4 Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an attacker to retrieve a hard-coded cryptographic key from … Sep 25, 2026
CVE-2026-62062 HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This issue affects Elementor Website Builder: from n/a through 4.3.1. Sep 25, 2026
CVE-2026-19775 MEDIUM 4.3 The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Sep 25, 2026
CVE-2026-14281 CRITICAL 9.8 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up … Sep 25, 2026
CVE-2026-97721 LOW 2.7 A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserAdminController.java of the component exportExcel/exportData. … Sep 25, 2026
CVE-2026-97818 HIGH 8.6 phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. Sep 25, 2026
CVE-2026-97764 LOW 3.7 django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of … Sep 25, 2026
CVE-2026-97737 HIGH 7.4 In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover. Sep 25, 2026
CVE-2026-97736 MEDIUM 5.4 tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression. Sep 25, 2026
CVE-2026-97735 HIGH 8.0 ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders. Sep 25, 2026