Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

46113
Total
3679
Critical
13638
High
13568
Medium
CVE ID Severity Score Description Published
CVE-2026-10035 MEDIUM 6.6 The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deserialization of … Aug 16, 2026
CVE-2026-19933 MEDIUM 6.3 A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes stack-based buffer … Aug 16, 2026
CVE-2026-19932 MEDIUM 6.3 A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /execute of the component NoticeController. The … Aug 16, 2026
CVE-2026-18432 CRITICAL 9.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because … Aug 16, 2026
CVE-2026-18385 MEDIUM 5.4 The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary … Aug 16, 2026
CVE-2026-17123 HIGH 8.8 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's … Aug 16, 2026
CVE-2026-16779 MEDIUM 4.3 The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.5. This is due to … Aug 16, 2026
CVE-2026-16099 HIGH 8.8 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all … Aug 16, 2026
CVE-2026-16098 CRITICAL 9.8 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. … Aug 16, 2026
CVE-2026-16079 MEDIUM 6.5 The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and including, … Aug 16, 2026
CVE-2026-15963 MEDIUM 6.5 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz Option … Aug 16, 2026
CVE-2026-15726 MEDIUM 6.4 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due … Aug 16, 2026
CVE-2026-15602 MEDIUM 4.9 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up … Aug 16, 2026
CVE-2026-15441 MEDIUM 5.3 The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute … Aug 16, 2026
CVE-2026-15066 MEDIUM 6.4 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 … Aug 16, 2026
CVE-2026-15009 MEDIUM 6.1 The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Aug 16, 2026
CVE-2026-15002 HIGH 7.2 The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 via the 'bm_woocommerce_css_editor_content' … Aug 16, 2026
CVE-2026-14524 CRITICAL 9.1 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all … Aug 16, 2026
CVE-2026-14498 HIGH 8.8 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. … Aug 16, 2026
CVE-2026-13358 MEDIUM 6.5 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … Aug 16, 2026
CVE-2026-13167 MEDIUM 4.3 The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in … Aug 16, 2026
CVE-2026-12905 MEDIUM 4.3 The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the … Aug 16, 2026
CVE-2026-12477 MEDIUM 4.4 The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions … Aug 16, 2026
CVE-2026-11780 MEDIUM 6.4 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_title' parameter … Aug 16, 2026
CVE-2025-10005 MEDIUM 4.3 The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up … Aug 16, 2026