Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41893
Total
3420
Critical
12384
High
12282
Medium
CVE ID Severity Score Description Published
CVE-2025-15694 UNKNOWN The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, … Sep 05, 2026
CVE-2025-15693 UNKNOWN The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the … Sep 05, 2026
CVE-2026-8625 MEDIUM 6.4 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom … Sep 05, 2026
CVE-2026-8623 MEDIUM 6.4 The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class … Sep 05, 2026
CVE-2026-86145 HIGH 8.2 PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check … Sep 05, 2026
CVE-2026-83628 MEDIUM 4.3 The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due … Sep 05, 2026
CVE-2026-83627 CRITICAL 9.8 The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and … Sep 05, 2026
CVE-2026-77263 HIGH 7.2 The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content … Sep 05, 2026
CVE-2026-77233 HIGH 7.2 The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content … Sep 05, 2026
CVE-2026-18404 MEDIUM 6.4 The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box … Sep 05, 2026
CVE-2026-13447 CRITICAL 9.8 The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to … Sep 05, 2026
CVE-2025-14945 MEDIUM 5.4 The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions … Sep 05, 2026
CVE-2026-86144 MEDIUM 5.6 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without … Sep 05, 2026
CVE-2026-86143 MEDIUM 6.9 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check … Sep 05, 2026
CVE-2026-86142 MEDIUM 6.9 In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. Sep 05, 2026
CVE-2026-86141 LOW 2.9 xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after … Sep 05, 2026
CVE-2026-86140 HIGH 8.0 In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. Sep 05, 2026
CVE-2026-86139 MEDIUM 6.9 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. Sep 05, 2026
CVE-2026-86138 MEDIUM 6.9 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. Sep 05, 2026
CVE-2026-86137 LOW 2.9 In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. Sep 05, 2026
CVE-2026-86100 MEDIUM 6.4 Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can … Sep 05, 2026
CVE-2026-52777 UNKNOWN YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This … Sep 05, 2026
CVE-2026-52775 HIGH 8.8 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() … Sep 05, 2026
CVE-2026-52774 MEDIUM 6.1 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using … Sep 05, 2026
CVE-2026-52773 MEDIUM 6.1 YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a … Sep 05, 2026