Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,675
Quick preset (or use dates below)
Clear Filters
Showing 2,201 - 2,220 of 13,436 CVEs
CVE-2026-8689 MEDIUM - 4.3

The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the wp_ajax_visualizer-create-chart...

Published: May 28, 2026
Source: NVD
CVE-2026-7526 MEDIUM - 4.3

The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key expo...

Published: May 28, 2026
Source: NVD
CVE-2026-7048 MEDIUM - 6.5

The Photo Gallery by 10Web โ€“ Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

Published: May 28, 2026
Source: NVD
CVE-2026-6937 MEDIUM - 5.3

The Appointment Booking Calendar โ€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments ...

Published: May 28, 2026
Source: NVD
CVE-2026-4334 MEDIUM - 6.4

The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all versions up to, and including, 4.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

Published: May 28, 2026
Source: NVD
CVE-2026-9618 MEDIUM - 4.3

The PeachPay โ€” Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or incorrect nonce validation on the peachpay_s...

Published: May 28, 2026
Source: NVD
CVE-2026-8682 MEDIUM - 4.3

The 3D Viewer โ€“ 3D Model Viewer โ€“ Augmented Reality โ€“ Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for aut...

Published: May 28, 2026
Source: NVD
CVE-2026-7660 MEDIUM - 6.1

The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attac...

Published: May 28, 2026
Source: NVD
CVE-2026-7651 MEDIUM - 5.3

The User Registration & Membership โ€“ Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is due to miss...

Published: May 28, 2026
Source: NVD
CVE-2026-7621 MEDIUM - 4.3

The SMTP2GO for WordPress โ€“ Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.16.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, wit...

Published: May 28, 2026
Source: NVD
CVE-2026-7552 MEDIUM - 5.3

The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to expose sensitive plugin co...

Published: May 28, 2026
Source: NVD
CVE-2026-6427 MEDIUM - 6.4

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HTML attribute quoting when processing crafted <video> elements, combined with unescaped output i...

Published: May 28, 2026
Source: NVD
CVE-2026-9803 MEDIUM - 5.3

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayI...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9802 MEDIUM - 6.8

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been r...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9801 MEDIUM - 4.9

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password ...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9798 MEDIUM - 4.3

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brut...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9673 MEDIUM - 6.8

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.

Published: May 28, 2026
Source: NVD
CVE-2026-9644 MEDIUM - 6.4

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. Th...

Published: May 28, 2026
Source: NVD
CVE-2026-7533 MEDIUM - 4.3

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens...

Published: May 28, 2026
Source: NVD
CVE-2026-3173 MEDIUM - 6.5

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user ha...

Published: May 28, 2026
Source: NVD