Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,706
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,041 - 8,060 of 13,016 CVEs
CVE-2026-25376 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows Reflected XSS.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

Vendor: eyecix
Product: Addon Jobsearch Chat
Published: Mar 25, 2026
Source: NVD
CVE-2026-25373 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/a through < 6.8.

Vendor: ProgressionStudios
Product: Vayvo
Published: Mar 25, 2026
Source: NVD
CVE-2026-25361 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through <= 5.1.4.

Vendor: magepeopleteam
Product: WpEvently
Published: Mar 25, 2026
Source: NVD
CVE-2026-25360 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

Vendor: rascals
Product: Vex
Published: Mar 25, 2026
Source: NVD
CVE-2026-25359 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.

Vendor: rascals
Product: Pendulum
Published: Mar 25, 2026
Source: NVD
CVE-2026-25358 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2.

Vendor: rascals
Product: Meloo
Published: Mar 25, 2026
Source: NVD
CVE-2026-25357 HIGH - 8.1

Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7.

Vendor: azzaroco
Product: Ultimate Membership Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-25356 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7.

Vendor: skygroup
Product: Yobazar
Published: Mar 25, 2026
Source: NVD
CVE-2026-25354 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Reebox reebox allows Reflected XSS.This issue affects Reebox: from n/a through < 1.4.8.

Vendor: skygroup
Product: Reebox
Published: Mar 25, 2026
Source: NVD
CVE-2026-25353 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Nooni nooni allows Reflected XSS.This issue affects Nooni: from n/a through < 1.5.1.

Vendor: skygroup
Product: Nooni
Published: Mar 25, 2026
Source: NVD
CVE-2026-25352 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyDecor mydecor allows Reflected XSS.This issue affects MyDecor: from n/a through < 1.5.9.

Vendor: skygroup
Product: MyDecor
Published: Mar 25, 2026
Source: NVD
CVE-2026-25351 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyMedi mymedi allows Reflected XSS.This issue affects MyMedi: from n/a through < 1.7.7.

Vendor: skygroup
Product: MyMedi
Published: Mar 25, 2026
Source: NVD
CVE-2026-25350 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Miti miti allows Reflected XSS.This issue affects Miti: from n/a through < 1.5.3.

Vendor: skygroup
Product: Miti
Published: Mar 25, 2026
Source: NVD
CVE-2026-25349 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Loobek loobek allows Reflected XSS.This issue affects Loobek: from n/a through < 1.5.2.

Vendor: skygroup
Product: Loobek
Published: Mar 25, 2026
Source: NVD
CVE-2026-25347 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acato WP REST Cache wp-rest-cache allows Stored XSS.This issue affects WP REST Cache: from n/a through <= 2026.1.0.

Vendor: Acato
Product: WP REST Cache
Published: Mar 25, 2026
Source: NVD
CVE-2026-25346 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro FAQ Builder AYS faq-builder-ays allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FAQ Builder AYS: from n/a through <= 1.8.2.

Vendor: Ays Pro
Product: FAQ Builder AYS
Published: Mar 25, 2026
Source: NVD
CVE-2026-25342 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kutethemes Boutique kute-boutique allows Reflected XSS.This issue affects Boutique: from n/a through < 2.4.6.

Vendor: kutethemes
Product: Boutique
Published: Mar 25, 2026
Source: NVD
CVE-2026-25341 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a through <= 1.1.45.

Vendor: RSJoomla!
Product: RSFirewall!
Published: Mar 25, 2026
Source: NVD
CVE-2026-25334 HIGH - 8.1

Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.

Vendor: wordpresschef
Product: Salon Booking System Pro
Published: Mar 25, 2026
Source: NVD
CVE-2026-25317 HIGH - 7.5

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5....

Vendor: tychesoftwares
Product: Print Invoice & Delivery Notes for WooCommerce
Published: Mar 25, 2026
Source: NVD