Total CVEs

138,363

Critical Severity

3,557

High Severity

12,776

Last 7 Days

1,903
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 12,906 CVEs
CVE-2026-8118 MEDIUM - 6.5

The Royal Addons for Elementor โ€“ Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary File Read in versions 1.7.1058 through 1.7.1059. This is due to the wpr_get_csv_handle() helper (introduced in version 1.7.1058 as part of the patch for CVE-2026-6229) falling back...

Published: Jun 19, 2026
Source: NVD
CVE-2026-7547 MEDIUM - 4.9

The Woosa โ€“ Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in versions up to and including 2.0.4. This is due to insufficient path sanitization in the render_logs_ui() function, which accepts a base64-encoded file name from the 'log_file...

Published: Jun 19, 2026
Source: NVD
CVE-2026-56132 MEDIUM - 6.9

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

Vendor: libexpat project
Product: libexpat
Published: Jun 19, 2026
Source: NVD
CVE-2026-56131 MEDIUM - 4.9

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).

Vendor: libexpat project
Product: libexpat
Published: Jun 19, 2026
Source: NVD
CVE-2026-4328 MEDIUM - 6.4

The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() to fetch a user-supplied URL without validating that the URL does not point to internal or private network resources in t...

Published: Jun 19, 2026
Source: NVD
CVE-2026-1856 MEDIUM - 6.4

The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-l...

Published: Jun 19, 2026
Source: NVD
CVE-2026-12644 MEDIUM - 5.3

Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken โ€” ...

Product: ts-deepmerge
Published: Jun 19, 2026
Source: NVD
CVE-2026-12430 MEDIUM - 4.4

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and ab...

Vendor: creativethemeshq
Product: Blocksy Companion
Published: Jun 19, 2026
Source: NVD
CVE-2026-12157 MEDIUM - 6.4

The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blockId attribute of the betterdocs/category-slate-layout Gutenberg block in versions up to, and including, 4.5.3. This is due to insuffi...

Vendor: wpdevteam
Product: BetterDocs โ€“ AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot
Published: Jun 19, 2026
Source: NVD
CVE-2026-11989 MEDIUM - 6.5

The Bit integrations โ€“ Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.7 via the upload_attachment. This makes it possible for unauthenticated attackers to make web re...

Vendor: bitpressadmin
Product: Bit integrations โ€“ Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation
Published: Jun 19, 2026
Source: NVD
CVE-2026-10779 MEDIUM - 4.3

The Classified Listing โ€“ Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action: rtcl_fb_gallery_i...

Vendor: techlabpro1
Product: Classified Listing โ€“ AI-Powered Classified ads & Business Directory
Published: Jun 19, 2026
Source: NVD
CVE-2026-10034 MEDIUM - 5.3

The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.39. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to supply an arbitr...

Vendor: legalweb
Product: WP DSGVO Tools (GDPR)
Published: Jun 19, 2026
Source: NVD
CVE-2026-11775 MEDIUM - 4.3

The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the useradminsimplifier_options_page function. This makes it possible for unauthenticated attackers to reset...

Vendor: adamsilverstein
Product: User Admin Simplifier
Published: Jun 19, 2026
Source: NVD
CVE-2026-52866 MEDIUM - 6.5

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

Vendor: Apollo Pharmacy
Product: Blood Glucose Monitoring System (Model No. APG-01 BT)
Published: Jun 19, 2026
Source: NVD
CVE-2026-50034 MEDIUM - 6.5

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

Vendor: Apollo Pharmacy
Product: Blood Glucose Monitoring System (Model No. APG-01 BT)
Published: Jun 19, 2026
Source: NVD
CVE-2026-12050 MEDIUM - 4.3

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.format() instead of being passed as a bound parameter, allowing an authenticated pgAdmin u...

Vendor: pgadmin.org
Product: pgAdmin 4
Published: Jun 19, 2026
Source: NVD
CVE-2026-12049 MEDIUM - 4.3

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed back inside pgAdmin, so an authenticated victim who clicked /mfa/validate?next=<extern...

Vendor: pgadmin.org
Product: pgAdmin 4
Published: Jun 19, 2026
Source: NVD
CVE-2026-56077 MEDIUM - 6.5

PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows attackers to access sensitive data by registering agents with duplicate IDs. Attackers can exploit the lack of agent ID uniqueness enforcement to share ledger instances and expose ...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-56074 MEDIUM - 5.5

PraisonAI before 1.5.128 caches tool approval decisions by tool name only, not by invocation arguments, allowing subsequent execute_command calls to bypass approval prompts. Attackers can exploit this by obtaining initial approval for a benign command, then silently exfiltrate API keys and credentia...

Vendor: PraisonAI
Product: PraisonAI
Published: Jun 18, 2026
Source: NVD
CVE-2026-49205 MEDIUM - 6.5

phpMyFAQ is an open source FAQ web application. Versions prior to 4.1.4 have Missing Authorization in the API CategoryController. CVE-2026-24421 addressed this in the BackupController by adding: $this->userHasPermission(PermissionType::BACKUP). The same fix was not applied to 4 other write endpo...

Vendor: thorsten
Product: phpMyFAQ
Published: Jun 18, 2026
Source: NVD