Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.6
CVE-2026-50644

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands int…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.8
CVE-2026-4275

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-12428

The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values()…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.1
CVE-2026-14372

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file d…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.2
CVE-2026-13441

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_back…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-5793

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticare…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-5955

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticare…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-1365

Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affe…

No fix yet
Fix from $1,600 2026-07-09
Unclassified CRITICAL 9.3
CVE-2026-2342

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp al…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified HIGH 7.5
CVE-2026-1989

Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Id…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-15158

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachmen…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-8996

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-7558

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and in…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-6910

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `h…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.2
CVE-2026-8848

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorizatio…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-4653

The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up t…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 8.1
CVE-2026-31985

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verificat…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-14343

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.2
CVE-2026-15000

The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all ve…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-13771

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all version…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-13450

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.1
CVE-2026-13334

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including,…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-13253

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/ad…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.6
CVE-2026-13080

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all ver…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-13011

The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-12418

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecur…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified CRITICAL 9.8
CVE-2026-14245

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc…

Mitigation only
Fix from $2,300 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-12406

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authori…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.4
CVE-2026-12170

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.5
CVE-2026-47840

A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harves…

Mitigation only
Fix from $1,950 2026-07-09