Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-97287 HIGH 8.5 Contributor SQL Injection in Event Tickets <= 5.29.5 versions. Sep 30, 2026
CVE-2026-97286 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions. Sep 30, 2026
CVE-2026-97285 MEDIUM 5.4 Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. Sep 30, 2026
CVE-2026-97282 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. Sep 30, 2026
CVE-2026-97279 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Polylang <= 3.8.9 versions. Sep 30, 2026
CVE-2026-97274 CRITICAL 9.8 Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. Sep 30, 2026
CVE-2026-97272 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. Sep 30, 2026
CVE-2026-97271 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. Sep 30, 2026
CVE-2026-97270 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in CMB2 <= 2.13.0 versions. Sep 30, 2026
CVE-2026-97267 MEDIUM 4.3 Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. Sep 30, 2026
CVE-2026-97266 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions. Sep 30, 2026
CVE-2026-97262 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions. Sep 30, 2026
CVE-2026-97261 MEDIUM 5.3 Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions. Sep 30, 2026
CVE-2026-97253 HIGH 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0. Sep 30, 2026
CVE-2026-97250 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. Sep 30, 2026
CVE-2026-97249 MEDIUM 5.3 Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. Sep 30, 2026
CVE-2026-97248 CRITICAL 9.8 Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. Sep 30, 2026
CVE-2026-97247 MEDIUM 6.5 Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. Sep 30, 2026
CVE-2026-97246 MEDIUM 4.9 Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. Sep 30, 2026
CVE-2026-97245 HIGH 7.2 Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions. Sep 30, 2026
CVE-2026-97244 HIGH 7.5 Contributor Path Traversal in Creator LMS <= 1.2.19 versions. Sep 30, 2026
CVE-2026-97243 MEDIUM 5.4 Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. Sep 30, 2026
CVE-2026-97242 MEDIUM 6.8 Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions. Sep 30, 2026
CVE-2026-97241 HIGH 7.5 Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. Sep 30, 2026
CVE-2026-97240 HIGH 7.5 Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. Sep 30, 2026