Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45656
Total
3653
Critical
13500
High
13451
Medium
CVE ID Severity Score Description Published
CVE-2026-16099 HIGH 8.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all … Aug 16, 2026
CVE-2026-16098 CRITICAL 9.8 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. … Aug 16, 2026
CVE-2026-16079 MEDIUM 6.5 The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, … Aug 16, 2026
CVE-2026-15963 MEDIUM 6.5 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option … Aug 16, 2026
CVE-2026-15726 MEDIUM 6.4 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due … Aug 16, 2026
CVE-2026-15602 MEDIUM 4.9 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up … Aug 16, 2026
CVE-2026-15441 MEDIUM 5.3 The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute … Aug 16, 2026
CVE-2026-15066 MEDIUM 6.4 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 … Aug 16, 2026
CVE-2026-15009 MEDIUM 6.1 The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Aug 16, 2026
CVE-2026-15002 HIGH 7.2 The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' … Aug 16, 2026
CVE-2026-14524 CRITICAL 9.1 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all … Aug 16, 2026
CVE-2026-14498 HIGH 8.8 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. … Aug 16, 2026
CVE-2026-13358 MEDIUM 6.5 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … Aug 16, 2026
CVE-2026-13167 MEDIUM 4.3 The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in … Aug 16, 2026
CVE-2026-12905 MEDIUM 4.3 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the … Aug 16, 2026
CVE-2026-12477 MEDIUM 4.4 The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … Aug 16, 2026
CVE-2026-11780 MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter … Aug 16, 2026
CVE-2025-10005 MEDIUM 4.3 The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … Aug 16, 2026
CVE-2026-2487 MEDIUM 4.4 The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due … Aug 16, 2026
CVE-2026-19930 MEDIUM 6.3 A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. … Aug 16, 2026
CVE-2026-19929 MEDIUM 6.3 A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation … Aug 16, 2026
CVE-2026-19928 MEDIUM 6.3 A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a … Aug 16, 2026
CVE-2026-19927 MEDIUM 6.3 A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload … Aug 16, 2026
CVE-2026-19926 HIGH 7.3 A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder … Aug 16, 2026
CVE-2026-19925 MEDIUM 4.7 A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument … Aug 16, 2026