Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54227
Total
4299
Critical
16114
High
15798
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-97637 | CRITICAL | 9.8 | The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. … | Oct 02, 2026 |
| CVE-2026-97634 | MEDIUM | 6.5 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, … | Oct 02, 2026 |
| CVE-2026-97342 | HIGH | 7.2 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in … | Oct 02, 2026 |
| CVE-2026-97338 | MEDIUM | 6.4 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to … | Oct 02, 2026 |
| CVE-2026-97336 | HIGH | 7.2 | The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to … | Oct 02, 2026 |
| CVE-2026-96871 | HIGH | 7.2 | The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due … | Oct 02, 2026 |
| CVE-2026-96647 | MEDIUM | 6.4 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up … | Oct 02, 2026 |
| CVE-2026-96578 | HIGH | 7.2 | The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up … | Oct 02, 2026 |
| CVE-2026-96567 | HIGH | 7.2 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 … | Oct 02, 2026 |
| CVE-2026-96566 | HIGH | 7.2 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'np1' Custom Field Parameter in all versions … | Oct 02, 2026 |
| CVE-2026-95817 | HIGH | 7.2 | The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 … | Oct 02, 2026 |
| CVE-2026-95670 | HIGH | 7.2 | The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and … | Oct 02, 2026 |
| CVE-2026-94432 | MEDIUM | 5.3 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … | Oct 02, 2026 |
| CVE-2026-93880 | MEDIUM | 6.1 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up … | Oct 02, 2026 |
| CVE-2026-93756 | HIGH | 7.2 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message … | Oct 02, 2026 |
| CVE-2026-63578 | UNKNOWN | — | Allocation of resources without limits in password-based private-key decryption (PbeUtilities.GenerateCipherParameters) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can … | Oct 02, 2026 |
| CVE-2026-63577 | UNKNOWN | — | Improper certificate validation in the directoryName name-constraint check (PkixNameConstraintValidator.WithinDNSubtree) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who controls, or … | Oct 02, 2026 |
| CVE-2026-63576 | UNKNOWN | — | Improper certificate validation in PkixNameConstraintValidator (ExtractHostFromURL) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a name-constrained subordinate CA, or anyone able to … | Oct 02, 2026 |
| CVE-2026-63575 | UNKNOWN | — | Loop with unreachable exit condition in the PKCS#12 key derivation (Pkcs12ParametersGenerator) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who … | Oct 02, 2026 |
| CVE-2026-63574 | UNKNOWN | — | Memory allocation with excessive size value in the OpenPGP signature and user attribute subpacket parsers (SignatureSubpacketsParser.ReadPacket, UserAttributeSubpacketsParser.ReadPacket) in Legion of the Bouncy Castle Inc. bc-csharp … | Oct 02, 2026 |
| CVE-2026-63573 | UNKNOWN | — | Observable discrepancy in the CMS RSA PKCS#1 v1.5 key-transport unwrap (KeyTransRecipientInformation.UnwrapKey) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows a remote attacker … | Oct 02, 2026 |
| CVE-2026-63572 | UNKNOWN | — | Allocation of resources without limits in PKCS#12 keystore loading (Pkcs12Store.Load) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can … | Oct 02, 2026 |
| CVE-2026-63571 | UNKNOWN | — | Improper verification of cryptographic signature in the attribute certificate path validator (PkixAttrCertPathValidator, also used by PkixAttrCertPathBuilder) in Legion of the Bouncy Castle Inc. bc-csharp before … | Oct 02, 2026 |
| CVE-2026-63570 | UNKNOWN | — | Loop with unreachable exit condition in Pkcs12Store.GetCertificateChain in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an attacker who can supply a crafted … | Oct 02, 2026 |
| CVE-2026-18036 | UNKNOWN | — | In Bouncy Castle for Java before 1.86, NTRU reduced secret values with the % operator in three helpers whose reference implementations are deliberately division-free, so … | Oct 02, 2026 |