Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-13225
Malicious HTML content could be injected into the email address of an
order, which pretix showed without sanitization on the confirmation page
for …
Mitigation only
MEDIUM 6.3
CVE-2026-13223
Our payment integration with Computop-based payment methods did not
properly validate payment status responses. An attacker could use a
successful …
Mitigation only
MEDIUM 6.3
CVE-2026-13222
Our payment integration with Oppwa-based payment methods did not
properly validate payment status responses. An attacker could use a
successful pay…
Mitigation only
MEDIUM 6.5
CVE-2026-57619
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57429
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
Mitigation only
HIGH 7.5
CVE-2026-56122
Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by sendi…
Mitigation only
HIGH 7.1
CVE-2026-56071
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
Mitigation only
HIGH 7.7
CVE-2026-56054
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
Mitigation only
HIGH 8.8
CVE-2026-56053
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
Mitigation only
HIGH 7.1
CVE-2026-56051
Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-56050
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
Thi…
No fix yet
HIGH 8.5
CVE-2026-56049
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
Mitigation only
HIGH 7.1
CVE-2026-56042
Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
Mitigation only
MEDIUM 5.4
CVE-2026-56023
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-56014
Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-56013
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
Mitigation only
HIGH 7.1
CVE-2026-56006
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
Mitigation only
HIGH 7.1
CVE-2026-56005
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-54849
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
Mitigation only
HIGH 8.3
CVE-2026-54848
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Da…
Mitigation only
HIGH 8.1
CVE-2026-54845
Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
Mitigation only
HIGH 7.5
CVE-2026-54844
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-54843
Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
Mitigation only
HIGH 8.1
CVE-2026-54842
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue a…
Mitigation only
HIGH 7.5
CVE-2026-54841
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
Mitigation only
HIGH 8.5
CVE-2026-54838
Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
Mitigation only
CRITICAL 9.3
CVE-2026-54836
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection.
This issue af…
Mitigation only
HIGH 7.5
CVE-2026-54830
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
Mitigation only
HIGH 7.5
CVE-2026-54829
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows B…
Mitigation only
HIGH 7.5
CVE-2026-54828
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
Mitigation only