Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66626 | HIGH | 7.6 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | Sep 17, 2026 |
| CVE-2026-66625 | HIGH | 7.6 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | Sep 17, 2026 |
| CVE-2026-66624 | HIGH | 7.6 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | Sep 17, 2026 |
| CVE-2026-66619 | HIGH | 7.6 | Administrator SQL Injection in Newsletters <= 4.18 versions. | Sep 17, 2026 |
| CVE-2026-66618 | HIGH | 7.6 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | Sep 17, 2026 |
| CVE-2026-66617 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | Sep 17, 2026 |
| CVE-2026-66608 | MEDIUM | 6.4 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | Sep 17, 2026 |
| CVE-2026-66580 | HIGH | 8.5 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | Sep 17, 2026 |
| CVE-2026-66579 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | Sep 17, 2026 |
| CVE-2026-66578 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | Sep 17, 2026 |
| CVE-2026-66577 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | Sep 17, 2026 |
| CVE-2026-66576 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | Sep 17, 2026 |
| CVE-2026-66575 | MEDIUM | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | Sep 17, 2026 |
| CVE-2026-66574 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | Sep 17, 2026 |
| CVE-2026-66573 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | Sep 17, 2026 |
| CVE-2026-66572 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | Sep 17, 2026 |
| CVE-2026-66571 | HIGH | 7.1 | Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. | Sep 17, 2026 |
| CVE-2026-62108 | CRITICAL | 9.8 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. | Sep 17, 2026 |
| CVE-2026-62104 | CRITICAL | 10.0 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | Sep 17, 2026 |
| CVE-2026-62101 | CRITICAL | 9.8 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | Sep 17, 2026 |
| CVE-2026-14850 | UNKNOWN | — | The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric … | Sep 17, 2026 |
| CVE-2026-92932 | UNKNOWN | — | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original … | Sep 17, 2026 |
| CVE-2026-92921 | MEDIUM | 4.9 | admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can … | Sep 17, 2026 |
| CVE-2026-92920 | MEDIUM | 5.4 | admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue … | Sep 17, 2026 |
| CVE-2026-92919 | HIGH | 8.1 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. … | Sep 17, 2026 |