Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,765
Quick preset (or use dates below)
Clear Filters
Showing 6,361 - 6,380 of 13,903 CVEs
CVE-2026-40740 MEDIUM - 5.4

Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.7.

Vendor: Themeum
Product: Tutor LMS
Published: Apr 15, 2026
Source: NVD
CVE-2026-40737 MEDIUM - 5.3

Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects COMPE: from n/a through <= 1.1.4.

Vendor: VillaTheme
Product: COMPE
Published: Apr 15, 2026
Source: NVD
CVE-2026-40734 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories Images categories-images allows DOM-Based XSS.This issue affects Categories Images: from n/a through <= 3.3.1.

Vendor: Zahlan
Product: Categories Images
Published: Apr 15, 2026
Source: NVD
CVE-2026-40730 MEDIUM - 5.3

Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6.

Vendor: ThemeGrill
Product: ThemeGrill Demo Importer
Published: Apr 15, 2026
Source: NVD
CVE-2026-40729 MEDIUM - 4.3

Missing Authorization vulnerability in bPlugins 3D viewer โ€“ Embed 3D Models 3d-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D viewer โ€“ Embed 3D Models: from n/a through <= 1.8.5.

Vendor: bPlugins
Product: 3D viewer โ€“ Embed 3D Models
Published: Apr 15, 2026
Source: NVD
CVE-2026-40728 MEDIUM - 4.3

Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Magazine Blocks: from n/a through <= 1.8.3.

Vendor: BlockArt
Product: Magazine Blocks
Published: Apr 15, 2026
Source: NVD
CVE-2026-28741 MEDIUM - 6.8

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious p...

Vendor: Mattermost
Product: Mattermost
Published: Apr 15, 2026
Source: NVD

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1....

Vendor: maven
Product: org.bouncycastle:bcprov-jdk14
Published: Apr 15, 2026
Source: NVD
CVE-2026-5717 MEDIUM - 6.4

The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_container' attribute of the 'include-post-by-cat' shortcode in all versions up to, and including, 0.4.200706 due to insufficient input sanitization and output escaping on user...

Published: Apr 15, 2026
Source: NVD
CVE-2026-4091 MEDIUM - 6.1

The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing nonce verification on the settings form in the func_page_main() function. This makes it possible for unauthenticated attackers to inject malicious web s...

Published: Apr 15, 2026
Source: NVD
CVE-2026-4011 MEDIUM - 6.4

The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions up to, and including, 0.1.0. This is due to insufficient input sanitization and output escaping on the 'id' shortcode attribute. Sp...

Published: Apr 15, 2026
Source: NVD
CVE-2026-4005 MEDIUM - 6.4

The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userhash' shortcode attribute in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() on the 'u...

Published: Apr 15, 2026
Source: NVD
CVE-2026-4002 MEDIUM - 4.3

The Petje.af plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 2.1.8. This is due to missing nonce validation in the ajax_revoke_token() function which handles the 'petjeaf_disconnect' AJAX action. The function performs destructive operati...

Published: Apr 15, 2026
Source: NVD
CVE-2026-3998 MEDIUM - 6.4

The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' shortcode attribute of the [jqmath] shortcode in all versions up to and including 1.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. T...

Published: Apr 15, 2026
Source: NVD
CVE-2026-3659 MEDIUM - 6.4

The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the [circliful] shortcode and via multiple shortcode attributes of the [circliful_direct] shortcode in all versions up to and including 1.2. This is due to insufficient in...

Published: Apr 15, 2026
Source: NVD
CVE-2026-3649 MEDIUM - 5.3

The Katalogportal PDF Sync plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.0. The katalogportal_popup_shortcode() function is registered as an AJAX handler via wp_ajax_katalogportal_shortcodePrinter but lacks any capability check (current_user_can(...

Published: Apr 15, 2026
Source: NVD
CVE-2026-3642 MEDIUM - 5.3

The e-shotโ„ข form builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.2. The eshot_form_builder_update_field_data() AJAX handler lacks any capability checks (current_user_can()) or nonce verification (check_ajax_referer()/wp_verify_nonce()). The...

Published: Apr 15, 2026
Source: NVD
CVE-2026-1782 MEDIUM - 5.3

The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation field value without recomputing or validating it against the configured form pric...

Published: Apr 15, 2026
Source: NVD
CVE-2026-6293 MEDIUM - 4.3

The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplied...

Published: Apr 15, 2026
Source: NVD
CVE-2026-5160 MEDIUM - 6.1

Versions of the package github.com/yuin/goldmark/renderer/html before 1.7.17 are vulnerable to Cross-site Scripting (XSS) due to improper ordering of URL validation and normalization. The renderer validates link destinations using a prefix-based check (IsDangerousURL) before resolving HTML entities....

Vendor: go
Product: github.com/yuin/goldmark/renderer/html
Published: Apr 15, 2026
Source: NVD