Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54256
Total
4300
Critical
16127
High
15827
Medium
CVE ID Severity Score Description Published
CVE-2026-96825 MEDIUM 4.2 Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. Sep 30, 2026
CVE-2026-96824 MEDIUM 6.8 Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. Sep 30, 2026
CVE-2026-96823 HIGH 7.5 Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. Sep 30, 2026
CVE-2026-96822 CRITICAL 9.3 Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. Sep 30, 2026
CVE-2026-96821 MEDIUM 6.3 Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions. Sep 30, 2026
CVE-2026-96820 HIGH 7.1 Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions. Sep 30, 2026
CVE-2026-96819 HIGH 7.1 Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions. Sep 30, 2026
CVE-2026-96818 HIGH 7.5 Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. Sep 30, 2026
CVE-2026-96817 HIGH 8.2 Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. Sep 30, 2026
CVE-2026-96816 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. Sep 30, 2026
CVE-2026-96815 HIGH 7.2 Custom role Privilege Escalation in Vitepos <= 3.5.0 versions. Sep 30, 2026
CVE-2026-96814 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions. Sep 30, 2026
CVE-2026-96450 MEDIUM 5.4 Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions. Sep 30, 2026
CVE-2026-96352 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. Sep 30, 2026
CVE-2026-96351 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. Sep 30, 2026
CVE-2026-96350 CRITICAL 9.8 Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. Sep 30, 2026
CVE-2026-96349 CRITICAL 10.0 Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. Sep 30, 2026
CVE-2026-96348 HIGH 7.5 Unauthenticated Broken Access Control in Bookly <= 28.2 versions. Sep 30, 2026
CVE-2026-96347 MEDIUM 6.5 Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions. Sep 30, 2026
CVE-2026-96346 HIGH 7.6 Author SQL Injection in WP ERP <= 1.17.9 versions. Sep 30, 2026
CVE-2026-96345 HIGH 7.6 Administrator SQL Injection in Estatik <= 4.3.5 versions. Sep 30, 2026
CVE-2026-96344 HIGH 7.2 Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. Sep 30, 2026
CVE-2026-96343 HIGH 7.2 Custom role PHP Object Injection in WP ERP <= 1.17.9 versions. Sep 30, 2026
CVE-2026-96338 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. Sep 30, 2026
CVE-2026-95616 HIGH 7.5 An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 … Sep 30, 2026