Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50353
Total
4061
Critical
14946
High
14711
Medium
CVE ID Severity Score Description Published
CVE-2026-14843 MEDIUM 5.3 The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated … Jul 31, 2026
CVE-2026-14834 MEDIUM 6.5 The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the … Jul 31, 2026
CVE-2026-14833 MEDIUM 6.8 The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption … Jul 31, 2026
CVE-2026-14830 HIGH 7.5 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order … Jul 31, 2026
CVE-2026-14554 MEDIUM 6.5 The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with … Jul 31, 2026
CVE-2026-14483 CRITICAL 9.8 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, … Jul 31, 2026
CVE-2026-14333 HIGH 7.5 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing … Jul 31, 2026
CVE-2026-14319 HIGH 7.5 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve … Jul 31, 2026
CVE-2026-14317 MEDIUM 5.3 The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part … Jul 31, 2026
CVE-2026-13609 HIGH 8.8 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags … Jul 31, 2026
CVE-2026-13393 LOW 3.5 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the … Jul 31, 2026
CVE-2026-13392 HIGH 7.2 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim … Jul 31, 2026
CVE-2026-12721 HIGH 8.6 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, … Jul 31, 2026
CVE-2026-12720 HIGH 7.5 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to … Jul 31, 2026
CVE-2026-12697 MEDIUM 5.4 The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing … Jul 31, 2026
CVE-2026-12695 HIGH 8.1 The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an … Jul 31, 2026
CVE-2026-12376 MEDIUM 4.3 The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access … Jul 31, 2026
CVE-2026-12251 HIGH 8.1 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration … Jul 31, 2026
CVE-2026-63223 CRITICAL 9.8 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename … Jul 31, 2026
CVE-2026-63222 HIGH 7.5 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote … Jul 31, 2026
CVE-2026-63221 CRITICAL 9.4 CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring … Jul 31, 2026
CVE-2026-56673 HIGH 7.5 ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to … Jul 31, 2026
CVE-2026-56672 HIGH 8.2 ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, … Jul 31, 2026
CVE-2026-56671 HIGH 7.5 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route … Jul 31, 2026
CVE-2026-56670 HIGH 8.2 ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline … Jul 31, 2026