Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41893
Total
3420
Critical
12384
High
12282
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-15694 | UNKNOWN | — | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, … | Sep 05, 2026 |
| CVE-2025-15693 | UNKNOWN | — | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the … | Sep 05, 2026 |
| CVE-2026-8625 | MEDIUM | 6.4 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom … | Sep 05, 2026 |
| CVE-2026-8623 | MEDIUM | 6.4 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class … | Sep 05, 2026 |
| CVE-2026-86145 | HIGH | 8.2 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check … | Sep 05, 2026 |
| CVE-2026-83628 | MEDIUM | 4.3 | The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due … | Sep 05, 2026 |
| CVE-2026-83627 | CRITICAL | 9.8 | The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and … | Sep 05, 2026 |
| CVE-2026-77263 | HIGH | 7.2 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content … | Sep 05, 2026 |
| CVE-2026-77233 | HIGH | 7.2 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content … | Sep 05, 2026 |
| CVE-2026-18404 | MEDIUM | 6.4 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box … | Sep 05, 2026 |
| CVE-2026-13447 | CRITICAL | 9.8 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to … | Sep 05, 2026 |
| CVE-2025-14945 | MEDIUM | 5.4 | The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions … | Sep 05, 2026 |
| CVE-2026-86144 | MEDIUM | 5.6 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without … | Sep 05, 2026 |
| CVE-2026-86143 | MEDIUM | 6.9 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check … | Sep 05, 2026 |
| CVE-2026-86142 | MEDIUM | 6.9 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | Sep 05, 2026 |
| CVE-2026-86141 | LOW | 2.9 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after … | Sep 05, 2026 |
| CVE-2026-86140 | HIGH | 8.0 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. | Sep 05, 2026 |
| CVE-2026-86139 | MEDIUM | 6.9 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | Sep 05, 2026 |
| CVE-2026-86138 | MEDIUM | 6.9 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | Sep 05, 2026 |
| CVE-2026-86137 | LOW | 2.9 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | Sep 05, 2026 |
| CVE-2026-86100 | MEDIUM | 6.4 | Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can … | Sep 05, 2026 |
| CVE-2026-52777 | UNKNOWN | — | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This … | Sep 05, 2026 |
| CVE-2026-52775 | HIGH | 8.8 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() … | Sep 05, 2026 |
| CVE-2026-52774 | MEDIUM | 6.1 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using … | Sep 05, 2026 |
| CVE-2026-52773 | MEDIUM | 6.1 | YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a … | Sep 05, 2026 |