Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2026-65560
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
No fix yet
HIGH 7.1
CVE-2026-65565
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
No fix yet
HIGH 7.1
CVE-2026-65544
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
No fix yet
HIGH 7.1
CVE-2026-65545
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
No fix yet
HIGH 7.1
CVE-2026-65509
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
No fix yet
HIGH 7.1
CVE-2026-65513
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
No fix yet
HIGH 7.1
CVE-2026-65515
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
No fix yet
HIGH 7.1
CVE-2026-65517
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
No fix yet
HIGH 7.1
CVE-2026-61963
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
No fix yet
HIGH 7.1
CVE-2026-61964
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
No fix yet
HIGH 7.1
CVE-2026-61982
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
No fix yet
HIGH 7.1
CVE-2026-61961
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
No fix yet
MEDIUM 6.5
CVE-2026-61959
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
No fix yet
HIGH 7.1
CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-28178
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
No fix yet
MEDIUM 5.9
CVE-2026-28179
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
No fix yet
HIGH 7.1
CVE-2026-28143
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28082
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
No fix yet
MEDIUM 6.4
CVE-2026-18501
The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cr…
No fix yet
MEDIUM 5.4
CVE-2026-8166
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu…
No fix yet
MEDIUM 6.4
CVE-2026-5158
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '…
No fix yet
MEDIUM 6.4
CVE-2026-5391
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' …
No fix yet
HIGH 7.2
CVE-2025-15028
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Si…
No fix yet
MEDIUM 6.4
CVE-2026-18400
The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'd…
No fix yet
HIGH 7.2
CVE-2026-18510
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment C…
No fix yet
MEDIUM 5.4
CVE-2026-16537
The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, al…
No fix yet
MEDIUM 5.4
CVE-2026-18395
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page…
No fix yet
MEDIUM 6.1
CVE-2025-15678
The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Autho…
No fix yet
MEDIUM 6.1
CVE-2026-11588
The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisat…
No fix yet