Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
24801
Total
1759
Critical
7594
High
7792
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-27412 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. | Jul 02, 2026 |
| CVE-2026-27408 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions. | Jul 02, 2026 |
| CVE-2026-27404 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions. | Jul 02, 2026 |
| CVE-2026-27402 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions. | Jul 02, 2026 |
| CVE-2026-27060 | HIGH | 8.8 | Contributor PHP Object Injection in ARMember Premium <= 7.0 versions. | Jul 02, 2026 |
| CVE-2026-14449 | UNKNOWN | — | u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components | Jul 02, 2026 |
| CVE-2026-11946 | HIGH | 7.5 | An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. … | Jul 02, 2026 |
| CVE-2025-69156 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions. | Jul 02, 2026 |
| CVE-2025-69155 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions. | Jul 02, 2026 |
| CVE-2025-69154 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions. | Jul 02, 2026 |
| CVE-2025-69153 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. | Jul 02, 2026 |
| CVE-2025-69152 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. | Jul 02, 2026 |
| CVE-2025-69134 | HIGH | 7.5 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. | Jul 02, 2026 |
| CVE-2025-69133 | HIGH | 7.5 | Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. | Jul 02, 2026 |
| CVE-2025-69132 | MEDIUM | 6.5 | Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions. | Jul 02, 2026 |
| CVE-2025-69094 | HIGH | 8.5 | Subscriber SQL Injection in Unicamp <= 2.2.2 versions. | Jul 02, 2026 |
| CVE-2025-66076 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions. | Jul 02, 2026 |
| CVE-2025-58902 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. | Jul 02, 2026 |
| CVE-2026-54431 | UNKNOWN | — | In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step … | Jul 02, 2026 |
| CVE-2026-54430 | UNKNOWN | — | liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_jose_jwks_aws_alb_resolve() function. The AWS ALB verifier reads both signer and kid from the unverified JWT header. If … | Jul 02, 2026 |
| CVE-2026-9834 | HIGH | 7.2 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all … | Jul 02, 2026 |
| CVE-2026-9188 | MEDIUM | 5.3 | The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to … | Jul 02, 2026 |
| CVE-2026-9145 | MEDIUM | 6.5 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up … | Jul 02, 2026 |
| CVE-2026-8482 | MEDIUM | 4.3 | A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible … | Jul 02, 2026 |
| CVE-2026-8441 | HIGH | 7.5 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up … | Jul 02, 2026 |