Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,106
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,401 - 2,420 of 47,325 CVEs
CVE-2026-59513 MEDIUM - 6.5

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

Vendor: masteriyo
Product: Masteriyo - LMS
Published: Jul 23, 2026
Source: NVD
CVE-2026-59512 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

Vendor: PI Web Solution
Product: Product Enquiry for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-57809 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.

Vendor: AffiliateWP
Product: AffiliateWP
Published: Jul 23, 2026
Source: NVD
CVE-2026-57808 MEDIUM - 6.5

Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.

Vendor: Saad Iqbal
Product: WP EasyPay
Published: Jul 23, 2026
Source: NVD
CVE-2026-57785 HIGH - 8.8

Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.

Vendor: ApusTheme
Product: ApusListing
Published: Jul 23, 2026
Source: NVD
CVE-2026-57784 CRITICAL - 9.6

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Vendor: Ninja Forms
Product: Ninja Forms File Uploads Extension
Published: Jul 23, 2026
Source: NVD
CVE-2026-57769 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

Vendor: ThemeGoods
Product: Grand Photography
Published: Jul 23, 2026
Source: NVD
CVE-2026-57767 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

Vendor: CodeCabin.io
Product: WP Google Maps Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57735 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.

Vendor: Soflyy
Product: Breakdance
Published: Jul 23, 2026
Source: NVD
CVE-2026-57717 MEDIUM - 6.5

Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions.

Vendor: knitpay
Product: Knit Pay
Published: Jul 23, 2026
Source: NVD
CVE-2026-57716 MEDIUM - 5.3

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

Vendor: videowhisper
Product: Broadcast Live Video
Published: Jul 23, 2026
Source: NVD
CVE-2026-57704 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

Vendor: StoreApps
Product: Smart Manager
Published: Jul 23, 2026
Source: NVD
CVE-2026-57703 MEDIUM - 6.3

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

Vendor: sunshinephotocart
Product: Sunshine Photo Cart
Published: Jul 23, 2026
Source: NVD
CVE-2026-57701 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

Vendor: WebCodingPlace
Product: Real Estate Manager Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57699 HIGH - 7.1

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

Vendor: bqworks
Product: Slider Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57696 HIGH - 7.1

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

Vendor: videowhisper
Product: Picture Gallery
Published: Jul 23, 2026
Source: NVD
CVE-2026-57626 HIGH - 7.1

Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.

Vendor: MailPoet
Product: MailPoet
Published: Jul 23, 2026
Source: NVD
CVE-2026-57428 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

Vendor: BoldGrid
Product: Sprout Clients
Published: Jul 23, 2026
Source: NVD
CVE-2026-57427 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

Vendor: Download Monitor
Product: Download Monitor - WPForms Lock
Published: Jul 23, 2026
Source: NVD
CVE-2026-57425 MEDIUM - 6.5

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

Vendor: wpdesk
Product: Autopay dla WooCommerce
Published: Jul 23, 2026
Source: NVD