Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54256
Total
4300
Critical
16127
High
15827
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92867 | HIGH | 8.8 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution. | Sep 30, 2026 |
| CVE-2026-88037 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up … | Sep 30, 2026 |
| CVE-2026-6806 | HIGH | 7.5 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all … | Sep 30, 2026 |
| CVE-2026-6173 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions … | Sep 30, 2026 |
| CVE-2026-6172 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions … | Sep 30, 2026 |
| CVE-2026-6171 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions … | Sep 30, 2026 |
| CVE-2026-6170 | MEDIUM | 6.4 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions … | Sep 30, 2026 |
| CVE-2026-16596 | MEDIUM | 6.5 | The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 … | Sep 30, 2026 |
| CVE-2026-14876 | MEDIUM | 6.4 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 … | Sep 30, 2026 |
| CVE-2026-11895 | MEDIUM | 6.4 | The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' … | Sep 30, 2026 |
| CVE-2026-102508 | UNKNOWN | — | Improper Verification of Cryptographic Signature and Improper Certificate Validation in the OPC UA driver of Apache PLC4X (PLC4J) allows an attacker in a network position … | Sep 30, 2026 |
| CVE-2026-97196 | CRITICAL | 9.1 | Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9. | Sep 30, 2026 |
| CVE-2026-89294 | HIGH | 7.5 | The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the 'ssa_locale' parameter … | Sep 30, 2026 |
| CVE-2026-97316 | MEDIUM | 5.8 | The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address … | Sep 30, 2026 |
| CVE-2026-96886 | MEDIUM | 5.3 | The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address … | Sep 30, 2026 |
| CVE-2026-94297 | LOW | 2.7 | The Media Library Organizer WordPress plugin before 2.1.4 does not verify that the requesting user holds the target taxonomy's management capability before creating a new … | Sep 30, 2026 |
| CVE-2026-94274 | MEDIUM | 5.3 | The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, … | Sep 30, 2026 |
| CVE-2026-93580 | MEDIUM | 5.3 | The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an … | Sep 30, 2026 |
| CVE-2026-92994 | HIGH | 8.8 | The Verge3D Publishing and E-Commerce WordPress plugin before 4.13.1 does not validate the contents of files uploaded through its file storage feature and serves them … | Sep 30, 2026 |
| CVE-2026-92424 | MEDIUM | 6.8 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they … | Sep 30, 2026 |
| CVE-2026-91832 | HIGH | 7.1 | The WP Mobile Menu WordPress plugin before 2.9 does not correctly verify the nonce on its settings import, so an attacker can import arbitrary WP … | Sep 30, 2026 |
| CVE-2026-91072 | MEDIUM | 4.4 | The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an … | Sep 30, 2026 |
| CVE-2026-91051 | MEDIUM | 6.6 | The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta … | Sep 30, 2026 |
| CVE-2026-90953 | MEDIUM | 4.3 | The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user … | Sep 30, 2026 |
| CVE-2026-89193 | HIGH | 7.5 | The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image … | Sep 30, 2026 |