Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56102
Total
4437
Critical
16640
High
16418
Medium
CVE ID Severity Score Description Published
CVE-2026-93984 MEDIUM 5.3 OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public … Sep 19, 2026
CVE-2026-93983 MEDIUM 5.0 OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted … Sep 19, 2026
CVE-2026-93982 LOW 3.3 OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application … Sep 19, 2026
CVE-2026-93981 MEDIUM 4.7 hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside … Sep 19, 2026
CVE-2026-78030 CRITICAL 9.8 DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes … Sep 19, 2026
CVE-2026-9858 MEDIUM 4.3 The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and … Sep 19, 2026
CVE-2026-9766 MEDIUM 4.3 The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the … Sep 19, 2026
CVE-2026-9613 MEDIUM 4.3 The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due … Sep 19, 2026
CVE-2026-9289 MEDIUM 5.3 The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 … Sep 19, 2026
CVE-2026-93742 CRITICAL 9.9 A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the … Sep 19, 2026
CVE-2026-8354 MEDIUM 6.4 The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, … Sep 19, 2026
CVE-2026-76579 MEDIUM 4.7 The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due … Sep 19, 2026
CVE-2026-5410 MEDIUM 6.4 The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is … Sep 19, 2026
CVE-2026-1256 MEDIUM 6.4 The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and … Sep 19, 2026
CVE-2026-1255 HIGH 7.5 The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX … Sep 19, 2026
CVE-2026-18346 MEDIUM 5.3 The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not … Sep 19, 2026
CVE-2026-9855 MEDIUM 6.5 The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 … Sep 19, 2026
CVE-2026-9832 MEDIUM 5.3 The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, … Sep 19, 2026
CVE-2026-9615 MEDIUM 4.3 The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() … Sep 19, 2026
CVE-2026-9232 MEDIUM 6.5 The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes … Sep 19, 2026
CVE-2026-87917 MEDIUM 6.1 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and … Sep 19, 2026
CVE-2026-85658 HIGH 8.1 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode … Sep 19, 2026
CVE-2026-7527 MEDIUM 4.7 The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and … Sep 19, 2026
CVE-2026-75959 MEDIUM 4.9 The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 … Sep 19, 2026
CVE-2026-6295 MEDIUM 4.9 The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is … Sep 19, 2026