Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2026-8866 MEDIUM 6.4 The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This … May 27, 2026
CVE-2026-8847 MEDIUM 6.4 The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input … May 27, 2026
CVE-2026-8846 MEDIUM 6.4 The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due … May 27, 2026
CVE-2026-8845 MEDIUM 6.4 The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is … May 27, 2026
CVE-2026-8844 MEDIUM 6.4 The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is … May 27, 2026
CVE-2026-8842 MEDIUM 6.4 The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This … May 27, 2026
CVE-2026-8837 MEDIUM 6.4 The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up … May 27, 2026
CVE-2026-8787 HIGH 8.8 The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due … May 27, 2026
CVE-2026-8760 CRITICAL 9.8 The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an … May 27, 2026
CVE-2026-8708 MEDIUM 4.3 The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing … May 27, 2026
CVE-2026-8707 MEDIUM 6.1 The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due … May 27, 2026
CVE-2026-8703 MEDIUM 6.4 The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to … May 27, 2026
CVE-2026-8702 MEDIUM 6.4 The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This … May 27, 2026
CVE-2026-8701 MEDIUM 6.4 The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. This … May 27, 2026
CVE-2026-8698 MEDIUM 6.4 The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the … May 27, 2026
CVE-2026-8048 MEDIUM 6.4 The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions … May 27, 2026
CVE-2026-8040 MEDIUM 6.4 The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up … May 27, 2026
CVE-2026-7614 MEDIUM 4.3 The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to … May 27, 2026
CVE-2026-6268 HIGH 7.1 The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the … May 27, 2026
CVE-2026-9236 MEDIUM 4.3 The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in … May 27, 2026
CVE-2026-8450 CRITICAL 9.1 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets … May 27, 2026
CVE-2026-6287 MEDIUM 5.4 The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple … May 27, 2026
CVE-2026-49000 HIGH 7.0 An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to … May 27, 2026
CVE-2025-14481 MEDIUM 4.3 The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to … May 27, 2026
CVE-2026-9022 MEDIUM 6.4 The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 … May 27, 2026