Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56102
Total
4437
Critical
16640
High
16418
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-93984 | MEDIUM | 5.3 | OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public … | Sep 19, 2026 |
| CVE-2026-93983 | MEDIUM | 5.0 | OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted … | Sep 19, 2026 |
| CVE-2026-93982 | LOW | 3.3 | OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application … | Sep 19, 2026 |
| CVE-2026-93981 | MEDIUM | 4.7 | hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside … | Sep 19, 2026 |
| CVE-2026-78030 | CRITICAL | 9.8 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes … | Sep 19, 2026 |
| CVE-2026-9858 | MEDIUM | 4.3 | The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and … | Sep 19, 2026 |
| CVE-2026-9766 | MEDIUM | 4.3 | The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the … | Sep 19, 2026 |
| CVE-2026-9613 | MEDIUM | 4.3 | The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due … | Sep 19, 2026 |
| CVE-2026-9289 | MEDIUM | 5.3 | The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 … | Sep 19, 2026 |
| CVE-2026-93742 | CRITICAL | 9.9 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the … | Sep 19, 2026 |
| CVE-2026-8354 | MEDIUM | 6.4 | The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, … | Sep 19, 2026 |
| CVE-2026-76579 | MEDIUM | 4.7 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due … | Sep 19, 2026 |
| CVE-2026-5410 | MEDIUM | 6.4 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is … | Sep 19, 2026 |
| CVE-2026-1256 | MEDIUM | 6.4 | The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and … | Sep 19, 2026 |
| CVE-2026-1255 | HIGH | 7.5 | The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX … | Sep 19, 2026 |
| CVE-2026-18346 | MEDIUM | 5.3 | The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not … | Sep 19, 2026 |
| CVE-2026-9855 | MEDIUM | 6.5 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 … | Sep 19, 2026 |
| CVE-2026-9832 | MEDIUM | 5.3 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, … | Sep 19, 2026 |
| CVE-2026-9615 | MEDIUM | 4.3 | The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() … | Sep 19, 2026 |
| CVE-2026-9232 | MEDIUM | 6.5 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes … | Sep 19, 2026 |
| CVE-2026-87917 | MEDIUM | 6.1 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and … | Sep 19, 2026 |
| CVE-2026-85658 | HIGH | 8.1 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode … | Sep 19, 2026 |
| CVE-2026-7527 | MEDIUM | 4.7 | The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and … | Sep 19, 2026 |
| CVE-2026-75959 | MEDIUM | 4.9 | The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 … | Sep 19, 2026 |
| CVE-2026-6295 | MEDIUM | 4.9 | The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is … | Sep 19, 2026 |