Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,106
Quick preset (or use dates below)
Clear Filters
Showing 2,381 - 2,400 of 150,920 CVEs
CVE-2026-61947 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Form Vibes โ€“ Database Manager for Forms <= 1.5.2 versions.

Vendor: WPVibes
Product: Form Vibes โ€“ Database Manager for Forms
Published: Jul 23, 2026
Source: NVD
CVE-2026-61946 MEDIUM - 6.5

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

Vendor: Easy Appointments
Product: Easy Appointments
Published: Jul 23, 2026
Source: NVD
CVE-2026-61945 MEDIUM - 6.5

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

Vendor: MultiVendorX
Product: WooCommerce Product Stock Alert
Published: Jul 23, 2026
Source: NVD
CVE-2026-61944 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.

Vendor: Bookly
Product: Bookly
Published: Jul 23, 2026
Source: NVD
CVE-2026-61943 HIGH - 7.5

Unauthenticated Broken Access Control in WPDM โ€“ Premium Packages <= 6.2.0 versions.

Vendor: Shahjada
Product: WPDM โ€“ Premium Packages
Published: Jul 23, 2026
Source: NVD
CVE-2026-59555 CRITICAL - 10.0

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

Vendor: Roland Barker
Product: Participants Database
Published: Jul 23, 2026
Source: NVD
CVE-2026-59554 HIGH - 7.5

Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.

Vendor: Ziina
Product: Ziina
Published: Jul 23, 2026
Source: NVD
CVE-2026-59547 HIGH - 7.5

Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.

Vendor: Easy Payment
Product: Payment Gateway for PayPal on WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-59545 HIGH - 8.1

Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.

Vendor: miniOrange
Product: miniOrange Discord Integration
Published: Jul 23, 2026
Source: NVD
CVE-2026-59544 CRITICAL - 9.8

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

Vendor: Thrive Themes Coupon
Product: Thrive Quiz Builder
Published: Jul 23, 2026
Source: NVD
CVE-2026-59543 CRITICAL - 9.9

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

Vendor: WPLake
Product: Advanced Views
Published: Jul 23, 2026
Source: NVD
CVE-2026-59542 HIGH - 7.7

Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

Vendor: WP Chill
Product: Kali Forms
Published: Jul 23, 2026
Source: NVD
CVE-2026-59541 HIGH - 8.8

Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.

Vendor: Hakan Ozevin
Product: WP BASE Booking
Published: Jul 23, 2026
Source: NVD
CVE-2026-59540 CRITICAL - 9.8

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

Vendor: Cozy Vision Technologies Pvt. Ltd.
Product: SMS Alert Order Notifications
Published: Jul 23, 2026
Source: NVD
CVE-2026-59526 CRITICAL - 9.3

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Vendor: RomanCode
Product: MapSVG
Published: Jul 23, 2026
Source: NVD
CVE-2026-59525 CRITICAL - 9.3

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

Vendor: Roland Barker
Product: Participants Database
Published: Jul 23, 2026
Source: NVD
CVE-2026-59524 MEDIUM - 6.5

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

Vendor: Sandhills Development, LLC
Product: Easy Digital Downloads
Published: Jul 23, 2026
Source: NVD
CVE-2026-59522 MEDIUM - 6.5

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

Vendor: weDevs
Product: WP ERP
Published: Jul 23, 2026
Source: NVD
CVE-2026-59517 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

Vendor: hassantafreshi
Product: Easy Form Builder
Published: Jul 23, 2026
Source: NVD
CVE-2026-59514 CRITICAL - 9.3

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

Vendor: MightyNetworks vs BuddyBoss
Product: Buddyboss Platform
Published: Jul 23, 2026
Source: NVD