Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55255
Total
4360
Critical
16420
High
16093
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-87079 | HIGH | 7.5 | Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each … | Sep 22, 2026 |
| CVE-2026-87078 | CRITICAL | 9.1 | Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it … | Sep 22, 2026 |
| CVE-2026-7622 | MEDIUM | 4.3 | The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and … | Sep 22, 2026 |
| CVE-2026-74766 | HIGH | 8.4 | Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The … | Sep 22, 2026 |
| CVE-2026-74765 | MEDIUM | 6.5 | Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode … | Sep 22, 2026 |
| CVE-2026-6922 | HIGH | 7.1 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, … | Sep 22, 2026 |
| CVE-2026-4123 | MEDIUM | 4.3 | The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to … | Sep 22, 2026 |
| CVE-2026-1645 | MEDIUM | 4.4 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and … | Sep 22, 2026 |
| CVE-2026-18439 | MEDIUM | 4.3 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, … | Sep 22, 2026 |
| CVE-2026-18345 | MEDIUM | 4.3 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in … | Sep 22, 2026 |
| CVE-2026-16778 | MEDIUM | 6.4 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up … | Sep 22, 2026 |
| CVE-2026-12995 | MEDIUM | 4.3 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value … | Sep 22, 2026 |
| CVE-2025-1281 | HIGH | 8.8 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions … | Sep 22, 2026 |
| CVE-2025-1280 | MEDIUM | 6.5 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes … | Sep 22, 2026 |
| CVE-2025-14487 | MEDIUM | 5.3 | The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. … | Sep 22, 2026 |
| CVE-2025-14486 | MEDIUM | 5.3 | The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. … | Sep 22, 2026 |
| CVE-2025-14484 | MEDIUM | 5.3 | The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, … | Sep 22, 2026 |
| CVE-2016-15059 | CRITICAL | 9.8 | Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the … | Sep 22, 2026 |
| CVE-2026-94504 | HIGH | 7.2 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break … | Sep 22, 2026 |
| CVE-2026-92438 | HIGH | 8.8 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, … | Sep 22, 2026 |
| CVE-2026-91827 | HIGH | 7.5 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when an administrator later exports form submissions to CSV, … | Sep 22, 2026 |
| CVE-2026-89412 | HIGH | 7.2 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on … | Sep 22, 2026 |
| CVE-2026-93655 | MEDIUM | 6.1 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due … | Sep 22, 2026 |
| CVE-2026-88788 | MEDIUM | 6.8 | The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does … | Sep 22, 2026 |
| CVE-2026-85653 | MEDIUM | 6.4 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 … | Sep 22, 2026 |