|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
4 days ago
|
|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
4 days ago
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
Remote Code Execution
Cwe 434
+1
|
4 days ago
|
|
CVE-2026-72696
|
|
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
|
High
|
Cwe 59
Grav
Symlink
Remote Code Execution
|
4 days ago
|
|
CVE-2026-72695
|
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
High
|
Path Traversal
Cwe 22
|
4 days ago
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
4 days ago
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
Privilege Escalation
Cwe 269
PHP
|
2 weeks ago
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
Cwe 78
Cockpit
PHP
Command Injection
|
2 weeks ago
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
2 weeks ago
|
|
CVE-2026-19758
|
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
High
|
Java
Path Traversal
Cwe 22
|
2 weeks ago
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
2 weeks ago
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
Authentication Bypass
|
2 weeks ago
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
3 weeks ago
|
|
CVE-2026-16636
|
|
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
3 weeks ago
|
|
CVE-2026-15991
|
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
High
|
PHP
WordPress
Remote Code Execution
Cwe 862
+1
|
3 weeks ago
|
|
CVE-2026-71291
|
|
Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
|
High
|
PHP
Remote Code Execution
Cwe 1336
Bolt Cms
|
3 weeks ago
|
|
CVE-2026-7520
|
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
High
|
WordPress
Cwe 862
PHP
Authentication Bypass
|
3 weeks ago
|
|
CVE-2026-7444
|
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
High
|
WordPress
Cwe 352
PHP
Cross-Site Request Forgery
|
3 weeks ago
|
|
CVE-2026-6627
|
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
High
|
PHP
WordPress
Cwe 862
Authentication Bypass
|
3 weeks ago
|
|
CVE-2026-6147
|
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
High
|
WordPress
Remote Code Execution
Cwe 434
PHP
|
3 weeks ago
|
|
CVE-2026-66473
|
|
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
|
High
|
Cwe 862
WordPress
PHP
Authentication Bypass
|
1 month ago
|
|
CVE-2026-65447
|
|
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
1 month ago
|
|
CVE-2026-65446
|
|
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
1 month ago
|
|
CVE-2026-65443
|
|
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
1 month ago
|
|
CVE-2026-65442
|
|
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
|
High
|
Server-Side Request Forgery
Cwe 918
WordPress
PHP
|
1 month ago
|
|
CVE-2026-65441
|
|
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
|
1 month ago
|
|
CVE-2026-65437
|
|
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <=...
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
1 month ago
|
|
CVE-2026-61953
|
|
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
|
High
|
Server-Side Request Forgery
Cwe 918
WordPress
PHP
|
1 month ago
|
|
CVE-2026-63030
KEV
|
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
Critical
|
WordPress
Remote Code Execution
SQL Injection
Cwe 436
+10
|
1 month ago
|
|
CVE-2026-58054
|
|
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
|
High
|
Cwe 269
Mybb
PHP
Privilege Escalation
|
2 months ago
|
|
CVE-2026-3652
|
|
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
2 months ago
|
|
CVE-2026-46489
|
|
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG f...
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every...
|
High
|
JavaScript
Cross-Site Scripting
Cwe 79
Cwe 434
|
2 months ago
|
|
CVE-2026-5415
|
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
High
|
WordPress
Authentication Bypass
Cwe 288
PHP
|
2 months ago
|
|
CVE-2026-5411
|
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
High
|
PHP
WordPress
Remote Code Execution
Cwe 434
|
2 months ago
|
|
CVE-2026-46392
|
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
|
High
|
PHP
JavaScript
Cwe 178
Cwe 434
+1
|
2 months ago
|
|
CVE-2026-1829
|
|
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
|
High
|
WordPress
Remote Code Execution
Cwe 94
PHP
|
2 months ago
|
|
CVE-2026-39552
|
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
High
|
PHP
Cwe 98
WordPress
Remote Code Execution
+1
|
2 months ago
|
|
CVE-2026-39553
|
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
High
|
PHP
Cwe 98
WordPress
Remote Code Execution
|
2 months ago
|
|
CVE-2026-39555
|
|
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
...
Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection.
...
|
High
|
Insecure Deserialization
Cwe 502
WordPress
PHP
|
2 months ago
|
|
CVE-2025-68886
|
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
High
|
PHP
Cwe 98
WordPress
Remote Code Execution
|
2 months ago
|
|
CVE-2025-69369
|
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
High
|
PHP
Cwe 98
WordPress
Local File Inclusion
|
2 months ago
|
|
CVE-2025-11262
|
|
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
|
High
|
WordPress
Cross-Site Scripting
Cwe 79
PHP
|
3 months ago
|
|
CVE-2026-42762
|
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
|
High
|
Cross-Site Scripting
Cwe 79
WordPress
PHP
|
3 months ago
|
|
CVE-2026-42760
|
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and...
Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and...
|
High
|
WordPress
Authentication Bypass
Cwe 288
|
3 months ago
|
|
CVE-2026-42753
|
|
Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows...
Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows...
|
High
|
Cwe 862
WordPress
Authentication Bypass
|
3 months ago
|
|
CVE-2026-42735
|
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
|
High
|
Authentication Bypass
Cwe 288
WordPress
PHP
|
3 months ago
|
|
CVE-2026-42736
|
|
Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp...
Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp...
|
High
|
Cwe 639
WordPress
IDOR
|
3 months ago
|
|
CVE-2026-42737
|
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
|
High
|
Path Traversal
Cwe 22
WordPress
PHP
|
3 months ago
|
|
CVE-2026-42745
|
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
|
High
|
Authentication Bypass
Cwe 288
WordPress
PHP
|
3 months ago
|
|
CVE-2026-42730
|
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
|
High
|
SQL Injection
Cwe 89
WordPress
PHP
|
3 months ago
|