Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-5356

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions u…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-6854

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all ve…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.2
CVE-2026-6818

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in a…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.4
CVE-2026-6742

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and inclu…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-14250

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to t…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-41042

Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's …

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 8.1
CVE-2026-3688

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in a…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.4
CVE-2025-14785

The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Store…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-6280

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Acc…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-9695

An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged ac…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 8.1
CVE-2026-12378

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP dese…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-9700

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due t…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-14500

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to…

No fix yet
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.3
CVE-2026-12097

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin n…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 7.8
CVE-2026-57895

Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folde…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.8
CVE-2026-56437

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected …

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14495

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14489

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ve…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-12153

The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugi…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified MEDIUM 6.1
CVE-2026-11798

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.4
CVE-2026-10570

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versi…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 7.5
CVE-2026-9842

The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This i…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-9701

The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified CRITICAL 9.1
CVE-2026-14487

The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDi…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14482

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists d…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.5
CVE-2026-14244

The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' pa…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-14158

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_v…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified CRITICAL 9.9
CVE-2026-56843

Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they d…

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 7.5
CVE-2026-51937

An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and th…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified MEDIUM 5.4
CVE-2026-36163

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the…

Mitigation only
Fix from $1,600 2026-07-07