Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28475
Total
2191
Critical
8537
High
8862
Medium
CVE ID Severity Score Description Published
CVE-2026-8877 MEDIUM 6.4 The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This … May 27, 2026
CVE-2026-8875 MEDIUM 6.4 The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, … May 27, 2026
CVE-2026-8873 MEDIUM 6.4 The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 2.4.1 due to … May 27, 2026
CVE-2026-8872 MEDIUM 6.4 The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up to, and including, 1.0.0. … May 27, 2026
CVE-2026-8871 MEDIUM 6.4 The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is … May 27, 2026
CVE-2026-8870 MEDIUM 6.4 The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up … May 27, 2026
CVE-2026-8869 MEDIUM 6.4 The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and including, 1.2.1. … May 27, 2026
CVE-2026-8868 MEDIUM 6.4 The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, and including, 1.4. This … May 27, 2026
CVE-2026-8867 MEDIUM 6.4 The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versions up to, and including, 1.0.0. … May 27, 2026
CVE-2026-8866 MEDIUM 6.4 The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This … May 27, 2026
CVE-2026-8847 MEDIUM 6.4 The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input … May 27, 2026
CVE-2026-8846 MEDIUM 6.4 The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due … May 27, 2026
CVE-2026-8845 MEDIUM 6.4 The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is … May 27, 2026
CVE-2026-8844 MEDIUM 6.4 The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is … May 27, 2026
CVE-2026-8842 MEDIUM 6.4 The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This … May 27, 2026
CVE-2026-8837 MEDIUM 6.4 The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up … May 27, 2026
CVE-2026-8787 HIGH 8.8 The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due … May 27, 2026
CVE-2026-8760 CRITICAL 9.8 The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an … May 27, 2026
CVE-2026-8708 MEDIUM 4.3 The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing … May 27, 2026
CVE-2026-8707 MEDIUM 6.1 The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due … May 27, 2026
CVE-2026-8703 MEDIUM 6.4 The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to … May 27, 2026
CVE-2026-8702 MEDIUM 6.4 The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This … May 27, 2026
CVE-2026-8701 MEDIUM 6.4 The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. This … May 27, 2026
CVE-2026-8698 MEDIUM 6.4 The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the … May 27, 2026
CVE-2026-8048 MEDIUM 6.4 The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions … May 27, 2026