Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-97239 MEDIUM 6.5 Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. Sep 30, 2026
CVE-2026-97238 MEDIUM 5.5 Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. Sep 30, 2026
CVE-2026-97237 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. Sep 30, 2026
CVE-2026-97236 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. Sep 30, 2026
CVE-2026-97235 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. Sep 30, 2026
CVE-2026-97197 HIGH 7.5 Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. Sep 30, 2026
CVE-2026-97079 MEDIUM 4.3 Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions. Sep 30, 2026
CVE-2026-97078 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions. Sep 30, 2026
CVE-2026-97077 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions. Sep 30, 2026
CVE-2026-97074 MEDIUM 4.3 Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. Sep 30, 2026
CVE-2026-97067 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. Sep 30, 2026
CVE-2026-97066 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions. Sep 30, 2026
CVE-2026-97065 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. Sep 30, 2026
CVE-2026-96838 HIGH 8.8 Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions. Sep 30, 2026
CVE-2026-96837 HIGH 8.8 Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions. Sep 30, 2026
CVE-2026-96836 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. Sep 30, 2026
CVE-2026-96835 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. Sep 30, 2026
CVE-2026-96834 MEDIUM 6.5 Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. Sep 30, 2026
CVE-2026-96833 HIGH 7.2 Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. Sep 30, 2026
CVE-2026-96832 HIGH 7.2 Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. Sep 30, 2026
CVE-2026-96831 HIGH 8.8 Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. Sep 30, 2026
CVE-2026-96830 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions. Sep 30, 2026
CVE-2026-96829 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions. Sep 30, 2026
CVE-2026-96828 HIGH 7.6 Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. Sep 30, 2026
CVE-2026-96827 HIGH 7.6 Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. Sep 30, 2026