Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-19728

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-upload…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-19726

The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contribu…

No fix yet
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-19725

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before usin…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.5
CVE-2026-19717

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, all…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-19714

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.1
CVE-2026-19712

The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instru…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-19711

The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allow…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-19613

The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom f…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19934

A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manip…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-18653

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrato…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.2
CVE-2026-17533

The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration import functionality to network administrators o…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-18402

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Bl…

No fix yet
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-18316

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.2
CVE-2026-17581

The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 'thermal' Template Engine in all …

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-16775

The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Sho…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-16758

The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and includin…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.7
CVE-2026-15384

The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.4
CVE-2026-13712

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attribu…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15790

The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.4 via the 'emd_mb_meta' …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15604

The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.10 via the 'series_bg_co…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-15056

The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is vulnerable to Directory Traversa…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.6
CVE-2026-10035

The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.7.1 via deseria…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19933

A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Cu…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19932

A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects the function GroovyShell.evaluate of the file /e…

No fix yet
Fix from $4,000 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-18432

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnera…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 5.4
CVE-2026-18385

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 8.8
CVE-2026-17123

The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form …

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 8.8
CVE-2026-16099

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_li…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-16098

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_han…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-16079

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and i…

No fix yet
Fix from $4,000 2026-08-16