Total CVEs

149,767

Critical Severity

4,827

High Severity

17,254

Last 7 Days

2,925
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 41 - 60 of 46,172 CVEs

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

Vendor: Unknown
Product: Tablesome Table
Published: Jul 28, 2026
Source: NVD

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Vendor: Unknown
Product: Database for Contact Form 7, WPforms, Elementor forms
Published: Jul 28, 2026
Source: NVD

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.

Vendor: Unknown
Product: Quiz and Survey Master (QSM)
Published: Jul 28, 2026
Source: NVD

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisi...

Vendor: Unknown
Product: Event Tickets and Registration
Published: Jul 28, 2026
Source: NVD

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

Vendor: Unknown
Product: TrueBooker
Published: Jul 28, 2026
Source: NVD
CVE-2026-14490 HIGH - 7.5

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a pub...

Vendor: deveasel
Product: Demi – One Click Demo Import, Backup & Site Migration
Published: Jul 28, 2026
Source: NVD
CVE-2026-12124 MEDIUM - 5.3

The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which...

Vendor: wpeverest
Product: PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer
Published: Jul 28, 2026
Source: NVD
CVE-2026-17528 MEDIUM - 6.1

Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when ...

Product: nice-select2
Published: Jul 28, 2026
Source: NVD
CVE-2026-17524 HIGH - 7.5

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only ...

Product: zip-lib
Published: Jul 28, 2026
Source: NVD
CVE-2026-66473 HIGH - 7.5

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

Vendor: Xendit
Product: Xendit Payment
Published: Jul 27, 2026
Source: NVD
CVE-2026-65448 MEDIUM - 6.5

Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

Vendor: AcyMailing Newsletter Team
Product: Anti Spam and list cleaner &#8211; AcyChecker
Published: Jul 27, 2026
Source: NVD
CVE-2026-65447 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

Vendor: Wasiliy Strecker / ContestGallery developer
Product: Contest Gallery
Published: Jul 27, 2026
Source: NVD
CVE-2026-65446 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

Vendor: WP Chill
Product: Kali Forms
Published: Jul 27, 2026
Source: NVD
CVE-2026-65445 MEDIUM - 6.5

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

Vendor: iSaumya
Product: Ad Invalid Click Protector (AICP)
Published: Jul 27, 2026
Source: NVD
CVE-2026-65443 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

Vendor: WP Media
Product: BackWPup
Published: Jul 27, 2026
Source: NVD
CVE-2026-65442 HIGH - 7.2

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

Vendor: Subtle Web Inc
Product: FormCraft
Published: Jul 27, 2026
Source: NVD
CVE-2026-65441 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

Vendor: Nexcess
Product: GiveWP
Published: Jul 27, 2026
Source: NVD
CVE-2026-65440 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

Vendor: Roxnor
Product: GetGenie
Published: Jul 27, 2026
Source: NVD
CVE-2026-65439 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

Vendor: Themefic
Product: Ultimate Addons for Contact Form 7
Published: Jul 27, 2026
Source: NVD
CVE-2026-65438 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

Vendor: Kofi Mokome
Product: Message Filter for Contact Form 7
Published: Jul 27, 2026
Source: NVD