Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 7,101 - 7,120 of 13,554 CVEs
CVE-2026-3594 MEDIUM - 5.3

The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '/wp-json/InkXEProductDesignerLite/orders' REST API endpoint. The endpoint is registered with 'permission_callback' set to '__r...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3480 MEDIUM - 6.5

The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. The plugin registers an admin_post action hook 'wp-blockade-shortcode-render' that maps to the render_shortcode_preview() function. This function lacks any capability che...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3477 MEDIUM - 5.3

The PZ Frontend Manager plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.0.6. The pzfm_user_request_action_callback() function, registered via the wp_ajax_pzfm_user_request_action action hook, lacks both capability checks and nonce verification. This ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3142 MEDIUM - 6.4

The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_var' parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

Published: Apr 08, 2026
Source: NVD
CVE-2026-2838 MEDIUM - 4.4

The Whole Enquiry Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜woowhole_success_msg’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Published: Apr 08, 2026
Source: NVD
CVE-2025-1794 MEDIUM - 5.4

The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5083 MEDIUM - 5.3

Ado::Sessions versions through 0.935 for Perl generates insecure session ids. The session id is generated from a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be guessed, if it is not leaked from...

Published: Apr 08, 2026
Source: NVD
CVE-2026-5082 MEDIUM - 5.3

Amon2::Plugin::Web::CSRFDefender versions from 7.00 through 7.03 for Perl generate an insecure session id. The generate_session_id function will attempt to read bytes from the /dev/urandom device, but if that is unavailable then it generates bytes using SHA-1 hash seeded with the built-in rand() fu...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3311 MEDIUM - 6.4

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Progress Bar shortcode in all versions up to, and including, 6.4.9 due to insufficient input sanitization ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-33273 MEDIUM - 4.7

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary file may be created by an administrator of the product. As a result, arbitrary code may be executed on the server.

Vendor: ICZ Corporation
Product: MATCHA INVOICE
Published: Apr 08, 2026
Source: NVD
CVE-2026-27787 MEDIUM - 5.4

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

Vendor: ICZ Corporation
Product: MATCHA SNS
Published: Apr 08, 2026
Source: NVD
CVE-2026-4785 MEDIUM - 6.4

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_caption' parameter in the [latepoint_resources] shortcode in versions up to and including 5.3.0. This is due to insufficient output escaping...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4341 MEDIUM - 6.4

The Prime Slider – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'follow_us_text' setting of the Mount widget in all versions up to, and including, 4.1.10. This is due to insufficient input sanitization and output escaping. Specifically, the...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4333 MEDIUM - 6.4

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'skin' attribute of the learn_press_courses shortcode in all versions up to and including 4.3.3. This is due to insufficient input sanitization and output escaping on the 's...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4299 MEDIUM - 5.3

The MainWP Child Reports plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.2.6. This is due to a missing capability check in the heartbeat_received() function in the Live_Update class. This makes it possible for authenticated attackers, with Subscriber...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3646 MEDIUM - 5.3

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to Missing Authorization via the plugin's webhook handler in all versions up to, and including, 3.3.13. This is due to missing authentication, authorization, and nonce verification on a standalone PHP file that dir...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3600 MEDIUM - 6.4

The Investi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'investi-announcements-accordion' shortcode's 'maximum-num-years' attribute in all versions up to, and including, 1.0.26. This is due to insufficient input sanitization and output escaping ...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3513 MEDIUM - 6.4

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode att...

Published: Apr 08, 2026
Source: NVD
CVE-2026-3239 MEDIUM - 6.4

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a...

Published: Apr 08, 2026
Source: NVD
CVE-2026-4379 MEDIUM - 6.4

The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in all versions up to, and including, 2.3.4. This is due to the plugin modifying gallery shortcode output to include the `group` attribute value without pr...

Published: Apr 08, 2026
Source: NVD