Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92244 | HIGH | 7.2 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / … | Oct 01, 2026 |
| CVE-2026-90992 | MEDIUM | 6.4 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, … | Oct 01, 2026 |
| CVE-2026-89427 | MEDIUM | 6.1 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions … | Oct 01, 2026 |
| CVE-2026-89424 | MEDIUM | 6.4 | The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due … | Oct 01, 2026 |
| CVE-2026-85235 | HIGH | 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field … | Oct 01, 2026 |
| CVE-2026-15983 | HIGH | 8.1 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, … | Oct 01, 2026 |
| CVE-2026-14995 | HIGH | 7.2 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient … | Oct 01, 2026 |
| CVE-2026-103664 | UNKNOWN | — | MISP contains a reflected cross-site scripting (XSS) vulnerability in the analyst data notes panel. The seed path parameter, supplied by the user via the URL, … | Oct 01, 2026 |
| CVE-2026-103662 | UNKNOWN | — | MISP contains a reflected cross-site scripting (XSS) vulnerability in the legacy taxonomy tag management confirmation forms (add tag and disable tag). The affected forms echoed … | Oct 01, 2026 |
| CVE-2026-103659 | UNKNOWN | — | MISP contains an authorization bypass in the event flattening feature. When a user requests an event with the flatten option enabled, the application removes the … | Oct 01, 2026 |
| CVE-2026-103656 | UNKNOWN | — | Rejected reason: this is rejected | Oct 01, 2026 |
| CVE-2026-103655 | UNKNOWN | — | MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its … | Oct 01, 2026 |
| CVE-2026-103431 | HIGH | 7.7 | colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local … | Oct 01, 2026 |
| CVE-2026-101925 | MEDIUM | 6.4 | The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter … | Oct 01, 2026 |
| CVE-2026-100184 | MEDIUM | 4.7 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based … | Oct 01, 2026 |
| CVE-2026-100179 | MEDIUM | 6.1 | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based … | Oct 01, 2026 |
| CVE-2026-93882 | HIGH | 7.5 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up … | Oct 01, 2026 |
| CVE-2026-89047 | MEDIUM | 6.1 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, … | Oct 01, 2026 |
| CVE-2026-78249 | UNKNOWN | — | A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, … | Oct 01, 2026 |
| CVE-2026-75957 | CRITICAL | 9.8 | The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, … | Oct 01, 2026 |
| CVE-2026-19902 | MEDIUM | 6.1 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions … | Oct 01, 2026 |
| CVE-2026-19807 | HIGH | 8.8 | The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This … | Oct 01, 2026 |
| CVE-2026-15989 | CRITICAL | 9.8 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. … | Oct 01, 2026 |
| CVE-2026-103651 | UNKNOWN | — | MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token … | Oct 01, 2026 |
| CVE-2026-103544 | MEDIUM | 6.3 | A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al … | Oct 01, 2026 |