Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-5356 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions u… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-6854 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all ve… Mitigation only Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-6818 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in a… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.4 CVE-2026-6742 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and inclu… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.3 CVE-2026-14250 The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to t… Mitigation only Fix from $1,6002026-07-08 CRITICAL 9.1 CVE-2026-41042 Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's … Mitigation only Fix from $2,3002026-07-08 HIGH 8.1 CVE-2026-3688 The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in a… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.4 CVE-2025-14785 The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Store… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-6280 Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Acc… Mitigation only Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-9695 An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged ac… Mitigation only Fix from $2,3002026-07-08 HIGH 8.1 CVE-2026-12378 The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP dese… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-9700 The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due t… Mitigation only Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-14500 The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due to… No fix yet Fix from $1,6002026-07-08 MEDIUM 5.3 CVE-2026-12097 The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin n… Mitigation only Fix from $1,6002026-07-08 HIGH 7.8 CVE-2026-57895 Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folde… Mitigation only Fix from $1,9502026-07-08 HIGH 7.8 CVE-2026-56437 Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected … Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-14495 The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.… Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-14489 The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all ve… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.8 CVE-2026-12153 The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugi… Mitigation only Fix from $2,3002026-07-08 MEDIUM 6.1 CVE-2026-11798 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2026-10570 The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versi… Mitigation only Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-9842 The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This i… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.8 CVE-2026-9701 The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores… Mitigation only Fix from $2,3002026-07-08 CRITICAL 9.1 CVE-2026-14487 The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the removeUploadDi… Mitigation only Fix from $2,3002026-07-08 HIGH 8.8 CVE-2026-14482 The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists d… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-14244 The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' pa… Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-14158 The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_v… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.9 CVE-2026-56843 Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they d… Mitigation only Fix from $2,3002026-07-08 HIGH 7.5 CVE-2026-51937 An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and th… Mitigation only Fix from $1,9502026-07-07 MEDIUM 5.4 CVE-2026-36163 An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the… Mitigation only Fix from $1,6002026-07-07