Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45656
Total
3653
Critical
13500
High
13451
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16099 | HIGH | 8.8 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all … | Aug 16, 2026 |
| CVE-2026-16098 | CRITICAL | 9.8 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. … | Aug 16, 2026 |
| CVE-2026-16079 | MEDIUM | 6.5 | The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, … | Aug 16, 2026 |
| CVE-2026-15963 | MEDIUM | 6.5 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option … | Aug 16, 2026 |
| CVE-2026-15726 | MEDIUM | 6.4 | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due … | Aug 16, 2026 |
| CVE-2026-15602 | MEDIUM | 4.9 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up … | Aug 16, 2026 |
| CVE-2026-15441 | MEDIUM | 5.3 | The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute … | Aug 16, 2026 |
| CVE-2026-15066 | MEDIUM | 6.4 | The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 … | Aug 16, 2026 |
| CVE-2026-15009 | MEDIUM | 6.1 | The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | Aug 16, 2026 |
| CVE-2026-15002 | HIGH | 7.2 | The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' … | Aug 16, 2026 |
| CVE-2026-14524 | CRITICAL | 9.1 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all … | Aug 16, 2026 |
| CVE-2026-14498 | HIGH | 8.8 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. … | Aug 16, 2026 |
| CVE-2026-13358 | MEDIUM | 6.5 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … | Aug 16, 2026 |
| CVE-2026-13167 | MEDIUM | 4.3 | The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in … | Aug 16, 2026 |
| CVE-2026-12905 | MEDIUM | 4.3 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the … | Aug 16, 2026 |
| CVE-2026-12477 | MEDIUM | 4.4 | The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … | Aug 16, 2026 |
| CVE-2026-11780 | MEDIUM | 6.4 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter … | Aug 16, 2026 |
| CVE-2025-10005 | MEDIUM | 4.3 | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … | Aug 16, 2026 |
| CVE-2026-2487 | MEDIUM | 4.4 | The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.4 due … | Aug 16, 2026 |
| CVE-2026-19930 | MEDIUM | 6.3 | A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. … | Aug 16, 2026 |
| CVE-2026-19929 | MEDIUM | 6.3 | A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation … | Aug 16, 2026 |
| CVE-2026-19928 | MEDIUM | 6.3 | A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a … | Aug 16, 2026 |
| CVE-2026-19927 | MEDIUM | 6.3 | A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload … | Aug 16, 2026 |
| CVE-2026-19926 | HIGH | 7.3 | A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-gateway-v1 of the component open-ils.fielder … | Aug 16, 2026 |
| CVE-2026-19925 | MEDIUM | 4.7 | A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument … | Aug 16, 2026 |