Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,096
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,461 - 2,480 of 47,325 CVEs
CVE-2026-64873 CRITICAL - 9.8

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

Vendor: regularlabs.com
Product: Cache Cleaner Pro extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-64872 MEDIUM - 6.5

Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

Vendor: regularlabs.com
Product: Cache Cleaner Pro extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-64871 MEDIUM - 5.4

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

Vendor: regularlabs.com
Product: Cache Cleaner extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-64799 HIGH - 7.5

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could ...

Vendor: regularlabs.com
Product: Articles Anywhere Pro extension for Joomla, Users Anywhere Pro extension for Joomla
Published: Jul 23, 2026
Source: NVD
CVE-2026-16078 MEDIUM - 6.5

The WCPOS โ€“ Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access and above, to ...

Vendor: kilbot
Product: WCPOS โ€“ Point of Sale (POS) plugin for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15906 MEDIUM - 6.5

The Premium Packages โ€“ Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex...

Vendor: codename065
Product: Premium Packages โ€“ Sell Digital Products Securely
Published: Jul 23, 2026
Source: NVD
CVE-2026-15827 MEDIUM - 5.3

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12. Both endpoints are reg...

Vendor: ataurr
Product: GutenKit โ€“ Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor
Published: Jul 23, 2026
Source: NVD
CVE-2026-15794 MEDIUM - 6.4

The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Vendor: berocket
Product: Grid/List View for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15786 MEDIUM - 4.9

The WP Encryption โ€“ One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for authenticated at...

Vendor: gowebsmarty
Product: WP Encryption โ€“ Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security
Published: Jul 23, 2026
Source: NVD
CVE-2026-15761 MEDIUM - 6.5

The Tickera โ€“ Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

Vendor: tickera
Product: Tickera โ€“ Sell Tickets & Manage Events
Published: Jul 23, 2026
Source: NVD
CVE-2026-15647 MEDIUM - 4.4

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

Vendor: berocket
Product: Brands for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15646 MEDIUM - 6.4

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with cont...

Vendor: berocket
Product: Brands for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-15448 MEDIUM - 6.5

The Tickera โ€“ Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Vendor: tickera
Product: Tickera โ€“ Sell Tickets & Manage Events
Published: Jul 23, 2026
Source: NVD
CVE-2026-15404 MEDIUM - 6.4

The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, which is hooked to admin_footer and echoe...

Vendor: niklaslindemann
Product: Bulk Page Generator โ€“ LPagery
Published: Jul 23, 2026
Source: NVD
CVE-2026-15394 MEDIUM - 6.4

The Header Footer Script Adder โ€“ Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes it possib...

Vendor: mahethekiller
Product: Header Footer Script Adder
Published: Jul 23, 2026
Source: NVD
CVE-2026-15348 MEDIUM - 6.3

The Premium Packages โ€“ Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function โ€” hooked to the unauthenticated WordPress `wp` action โ€” decoding the at...

Vendor: codename065
Product: Premium Packages โ€“ Sell Digital Products Securely
Published: Jul 23, 2026
Source: NVD
CVE-2026-15017 HIGH - 8.8

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined wit...

Vendor: mdjm
Product: MDJM Event Management
Published: Jul 23, 2026
Source: NVD
CVE-2026-15015 CRITICAL - 9.8

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to...

Vendor: cascadiawebservices
Product: MountDev AI MCP Connector for WordPress
Published: Jul 23, 2026
Source: NVD
CVE-2026-15011 CRITICAL - 9.8

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes...

Vendor: emarket-design
Product: Customer Support Ticket System & Helpdesk
Published: Jul 23, 2026
Source: NVD
CVE-2026-14481 MEDIUM - 6.4

The Equalize Digital Accessibility Checker โ€“ WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This ma...

Vendor: equalizedigital
Product: Equalize Digital Accessibility Checker โ€“ WCAG, ADA, EAA and Section 508 compliance
Published: Jul 23, 2026
Source: NVD