Total CVEs

111,119

Critical Severity

796

High Severity

2,523

Last 7 Days

1,220
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 41 - 60 of 7,524 CVEs
CVE-2026-1932 MEDIUM - 5.3

The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update-appointment REST API endpoint in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to m...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2469 HIGH - 7.6

Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2144 HIGH - 8.1

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads direct...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2027 MEDIUM - 4.4

The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AMP Custom CSS setting in all versions up to, and including, 1.0.49 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1983 MEDIUM - 4.3

The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing nonce validation on the event deletion functionality. This makes it possible for unauthenticated attackers to delete arbitrary event...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1912 MEDIUM - 6.4

The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'ctdoi' shortcode in all versions up to, and including, 0.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1904 MEDIUM - 6.4

The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'accordion' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1754 MEDIUM - 6.1

The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1164 MEDIUM - 6.1

The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜message’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level acces...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0692 HIGH - 7.5

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-contro...

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD
CVE-2025-14608 MEDIUM - 5.3

The WP Last Modified Info plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.5. This is due to the plugin not validating a user's access to a post before modifying its metadata in the 'bulk_save' AJAX action. This makes it ...

Vendor: infosatech
Product: WP Last Modified Info
Published: Feb 14, 2026
Source: NVD