Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52699 | HIGH | 7.5 | Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. | Jun 15, 2026 |
| CVE-2026-52697 | HIGH | 8.5 | Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. | Jun 15, 2026 |
| CVE-2026-52695 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. | Jun 15, 2026 |
| CVE-2026-52694 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. | Jun 15, 2026 |
| CVE-2026-52693 | CRITICAL | 9.3 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | Jun 15, 2026 |
| CVE-2026-52692 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. | Jun 15, 2026 |
| CVE-2026-49781 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. | Jun 15, 2026 |
| CVE-2026-49780 | HIGH | 8.8 | Customer Privilege Escalation in Dokan <= 5.0.2 versions. | Jun 15, 2026 |
| CVE-2026-49776 | CRITICAL | 9.3 | Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. | Jun 15, 2026 |
| CVE-2026-49775 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. | Jun 15, 2026 |
| CVE-2026-49773 | MEDIUM | 6.5 | Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. | Jun 15, 2026 |
| CVE-2026-49770 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | Jun 15, 2026 |
| CVE-2026-49769 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. | Jun 15, 2026 |
| CVE-2026-49768 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. | Jun 15, 2026 |
| CVE-2026-49766 | CRITICAL | 9.9 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | Jun 15, 2026 |
| CVE-2026-49765 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | Jun 15, 2026 |
| CVE-2026-49764 | CRITICAL | 9.8 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. | Jun 15, 2026 |
| CVE-2026-49763 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. | Jun 15, 2026 |
| CVE-2026-49112 | HIGH | 7.5 | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. | Jun 15, 2026 |
| CVE-2026-49110 | HIGH | 7.5 | Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions. | Jun 15, 2026 |
| CVE-2026-49109 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. | Jun 15, 2026 |
| CVE-2026-49106 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. | Jun 15, 2026 |
| CVE-2026-49105 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | Jun 15, 2026 |
| CVE-2026-49104 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions. | Jun 15, 2026 |
| CVE-2026-49085 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions. | Jun 15, 2026 |