Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 61 - 80 of 7,545 CVEs
CVE-2025-14852 MEDIUM - 4.3

The MDirector Newsletter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.8. This is due to missing nonce verification on the mdirectorNewsletterSave function. This makes it possible for unauthenticated attackers to update the plugin's s...

Vendor: antevenio
Product: MDirector Newsletter
Published: Feb 14, 2026
Source: NVD
CVE-2026-1932 MEDIUM - 5.3

The Appointment Booking Calendar Plugin – Bookr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update-appointment REST API endpoint in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to m...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2469 HIGH - 7.6

Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2144 HIGH - 8.1

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads direct...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2027 MEDIUM - 4.4

The AMP Enhancer – Compatibility Layer for Official AMP Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AMP Custom CSS setting in all versions up to, and including, 1.0.49 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1983 MEDIUM - 4.3

The SEATT: Simple Event Attendance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missing nonce validation on the event deletion functionality. This makes it possible for unauthenticated attackers to delete arbitrary event...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1912 MEDIUM - 6.4

The Citations tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in the 'ctdoi' shortcode in all versions up to, and including, 0.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1904 MEDIUM - 6.4

The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'accordion' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1754 MEDIUM - 6.1

The personal-authors-category plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1164 MEDIUM - 6.1

The Easy Voice Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜message’ parameter in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level acces...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0692 HIGH - 7.5

The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.0. This is due to the plugin relying on WooCommerce's `WC_Geolocation::get_ip_address()` function to validate IPN requests, which trusts user-contro...

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD

Rejected reason: Not used

Published: Feb 14, 2026
Source: NVD