Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-4338
The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/schedule…
Activitypub
8.0.2+
MEDIUM 6.1
CVE-2023-54332
Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the p…
Jetpack
No fix yet
CRITICAL 9.1
CVE-2024-6584
The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
Jetpack Boost
3.4.7+
MEDIUM 5.9
CVE-2024-10076
The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching i…
Jetpack
3.4.8 / 13.8+
MEDIUM 5.6
CVE-2024-10075
The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which cou…
Jetpack
13.8+
MEDIUM 5.3
CVE-2025-0466
The Sensei LMS WordPress plugin before 4.24.4 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak sensei_e…
Sensei Lms
4.24.4+
MEDIUM 6.1
CVE-2024-10858
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leadin…
Jetpack
14.1+
MEDIUM 6.1
CVE-2024-10103
In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of…
Mailpoet
5.3.2+
HIGH 8.8
CVE-2024-43968
Broken Access Control vulnerability in Automattic Newspack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects…
Newspack
3.8.7+
MEDIUM 5.3
CVE-2024-7786
The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthenticated attackers to leak email t…
Sensei Lms
4.24.2+
MEDIUM 5.4
CVE-2024-43949
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic GHActivity allows Stored XSS.…
Ghacitivity
after 1.5.0
MEDIUM 5.4
CVE-2024-37474
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1.
Newspack Ads
1.47.2+
MEDIUM 5.4
CVE-2024-37476
Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2…
Newspack Popups
2.31.2+
HIGH 8.8
CVE-2023-47788
Missing Authorization vulnerability in Automattic Jetpack.This issue affects Jetpack: from n/a before 12.7.
Jetpack
12.7+
MEDIUM 5.4
CVE-2024-4392
The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortco…
Jetpack
13.4+
MEDIUM 5.4
CVE-2023-47774
Improper Restriction of Rendered UI Layers or Frames vulnerability in Automattic Jetpack allows Clickjacking.This issue affects Jetpack: from n/a bef…
Jetpack
12.7+
HIGH 8.8
CVE-2023-51489
Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dash…
Crowdsignal Dashboard
3.1.0+
MEDIUM 5.4
CVE-2023-50875
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Sensei LMS – Online Courses, Quizzes…
Sensei Lms
after 4.17.0
MEDIUM 6.1
CVE-2023-51488
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls,…
Crowdsignal Dashboard
after 3.0.11
CRITICAL 9.8
CVE-2023-51502
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Strip…
Woocommerce Stripe
after 7.6.1
HIGH 7.5
CVE-2023-51503
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …
Woopayments
6.7.0+
MEDIUM 5.4
CVE-2023-50879
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows…
Wordpress.com Editing Toolkit
after 3.78784
HIGH 7.5
CVE-2023-32747
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a …
Woocommerce Bookings
after 1.15.78
CRITICAL 9.8
CVE-2023-35915
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooPayments – Fully Integrated Solut…
Woopayments
5.9.1+
HIGH 7.5
CVE-2023-35914
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Woo Subscriptions.This issue affects Woo Subscriptions: from n/a throug…
Woocommerce Subscriptions
5.1.3+
HIGH 7.5
CVE-2023-35916
Authorization Bypass Through User-Controlled Key vulnerability in Automattic WooPayments – Fully Integrated Solution Built and Supported by Woo.This …
Woopayments
5.9.1+
HIGH 8.1
CVE-2023-35876
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a thro…
Woocommerce Square
3.8.2+
HIGH 7.5
CVE-2023-37871
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce GoCardless.This issue affects GoCardless: from n/a through 2.5.6.
Woocommerce Gocardless
2.5.7+
HIGH 8.8
CVE-2023-47787
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.
Woocommerce Bookings
2.0.4+
HIGH 8.8
CVE-2023-47789
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a t…
Canada Post Shipping Method
2.8.4+