Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25962
Total
1947
Critical
7926
High
8184
Medium
CVE ID Severity Score Description Published
CVE-2026-57634 MEDIUM 4.3 Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions. Jun 26, 2026
CVE-2026-57633 MEDIUM 5.3 Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions. Jun 26, 2026
CVE-2026-57632 MEDIUM 5.4 Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. Jun 26, 2026
CVE-2026-57631 HIGH 7.6 Administrator SQL Injection in Popup box <= 6.0.1 versions. Jun 26, 2026
CVE-2026-57630 MEDIUM 5.3 Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions. Jun 26, 2026
CVE-2026-57629 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions. Jun 26, 2026
CVE-2026-57628 HIGH 7.6 Administrator SQL Injection in WP All Import <= 4.0.1 versions. Jun 26, 2026
CVE-2026-57627 MEDIUM 4.9 Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions. Jun 26, 2026
CVE-2026-57622 MEDIUM 4.3 Subscriber Broken Access Control in WPCafe <= 3.0.14 versions. Jun 26, 2026
CVE-2026-57618 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions. Jun 26, 2026
CVE-2026-57617 MEDIUM 6.5 Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions. Jun 26, 2026
CVE-2026-57527 HIGH 8.8 Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve … Jun 26, 2026
CVE-2026-57431 MEDIUM 6.5 Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions. Jun 26, 2026
CVE-2026-57430 MEDIUM 4.3 Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions. Jun 26, 2026
CVE-2026-57325 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in NanoMag <= 1.8 versions. Jun 26, 2026
CVE-2026-57324 MEDIUM 6.5 Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions. Jun 26, 2026
CVE-2026-57323 MEDIUM 5.8 Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions. Jun 26, 2026
CVE-2026-57322 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in weMail <= 2.1.2 versions. Jun 26, 2026
CVE-2026-57321 HIGH 7.1 Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions. Jun 26, 2026
CVE-2026-57319 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in FOX <= 1.4.8 versions. Jun 26, 2026
CVE-2026-57318 MEDIUM 6.5 Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions. Jun 26, 2026
CVE-2026-57317 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. Jun 26, 2026
CVE-2026-57316 MEDIUM 6.5 Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions. Jun 26, 2026
CVE-2026-57315 HIGH 8.5 Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions. Jun 26, 2026
CVE-2026-57314 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions. Jun 26, 2026