Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2026-57357
Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.
No fix yet
HIGH 7.1
CVE-2026-57356
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57355
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57354
Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
No fix yet
MEDIUM 6.5
CVE-2026-57353
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
Mitigation only
HIGH 7.1
CVE-2026-57351
Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-57350
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-57349
Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
Mitigation only
HIGH 7.2
CVE-2026-57348
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57347
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
No fix yet
HIGH 7.1
CVE-2026-57345
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
Mitigation only
HIGH 7.1
CVE-2026-57344
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-57343
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57342
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
Mitigation only
HIGH 8.8
CVE-2026-56037
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection.
This issue affects Themify Popup: from n/a through…
Mitigation only
MEDIUM 6.5
CVE-2026-49779
Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal.
This issue affects Tax Exempt for WooCommerce:…
Mitigation only
HIGH 8.1
CVE-2026-42382
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
Mitigation only
HIGH 7.5
CVE-2026-39448
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Mitigation only
CRITICAL 9.1
CVE-2026-27436
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-27433
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
Mitigation only
HIGH 7.1
CVE-2026-27430
Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
No fix yet
HIGH 7.1
CVE-2026-27426
Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
Mitigation only
HIGH 7.1
CVE-2026-27425
Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
Mitigation only
CRITICAL 9.9
CVE-2026-27419
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
No fix yet
HIGH 8.8
CVE-2026-27414
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Mitigation only
HIGH 8.1
CVE-2026-27412
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
Mitigation only
HIGH 7.1
CVE-2026-27408
Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-27404
Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
Mitigation only
HIGH 7.1
CVE-2026-27402
Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions.
Mitigation only
HIGH 8.8
CVE-2026-27060
Deserialization of Untrusted Data vulnerability in Repute Infosystems ARMember Premium allows Object Injection.
This issue affects ARMember Premium:…
Mitigation only