Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50589
Total
4065
Critical
14978
High
14744
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13344 | MEDIUM | 4.8 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, … | Jul 30, 2026 |
| CVE-2026-13330 | MEDIUM | 6.1 | The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, … | Jul 30, 2026 |
| CVE-2026-13178 | HIGH | 7.5 | The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked … | Jul 30, 2026 |
| CVE-2026-13145 | MEDIUM | 4.3 | The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing … | Jul 30, 2026 |
| CVE-2026-13143 | MEDIUM | 5.3 | The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing … | Jul 30, 2026 |
| CVE-2026-12687 | HIGH | 7.5 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to … | Jul 30, 2026 |
| CVE-2026-12500 | HIGH | 7.5 | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress … | Jul 30, 2026 |
| CVE-2026-11881 | MEDIUM | 6.1 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline … | Jul 30, 2026 |
| CVE-2026-11870 | MEDIUM | 5.4 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting … | Jul 30, 2026 |
| CVE-2026-11867 | MEDIUM | 6.5 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated … | Jul 30, 2026 |
| CVE-2026-11782 | MEDIUM | 5.9 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that … | Jul 30, 2026 |
| CVE-2026-67248 | UNKNOWN | — | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before … | Jul 30, 2026 |
| CVE-2026-67247 | UNKNOWN | — | A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated … | Jul 30, 2026 |
| CVE-2026-67246 | UNKNOWN | — | A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before … | Jul 30, 2026 |
| CVE-2026-67245 | UNKNOWN | — | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated … | Jul 30, 2026 |
| CVE-2026-1360 | HIGH | 7.5 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the … | Jul 30, 2026 |
| CVE-2026-16610 | CRITICAL | 9.8 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via … | Jul 30, 2026 |
| CVE-2026-14356 | HIGH | 8.8 | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin … | Jul 30, 2026 |
| CVE-2026-67244 | UNKNOWN | — | A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through … | Jul 30, 2026 |
| CVE-2026-48449 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. … | Jul 30, 2026 |
| CVE-2026-48448 | HIGH | 8.6 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to … | Jul 30, 2026 |
| CVE-2026-1982 | MEDIUM | 5.3 | The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to … | Jul 30, 2026 |
| CVE-2026-18188 | UNKNOWN | — | A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may … | Jul 30, 2026 |
| CVE-2026-18187 | UNKNOWN | — | A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an … | Jul 30, 2026 |
| CVE-2026-18186 | UNKNOWN | — | A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written … | Jul 30, 2026 |