Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,061 - 8,080 of 13,016 CVEs
CVE-2026-25309 HIGH - 7.5

Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.

Vendor: PublishPress
Product: PublishPress Authors
Published: Mar 25, 2026
Source: NVD
CVE-2026-25306 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4.

Vendor: 8theme
Product: XStore Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-25304 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Jaroti jaroti allows Reflected XSS.This issue affects Jaroti: from n/a through < 1.4.8.

Vendor: skygroup
Product: Jaroti
Published: Mar 25, 2026
Source: NVD
CVE-2026-25033 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uixthemes Motta Addons motta-addons allows Reflected XSS.This issue affects Motta Addons: from n/a through < 1.6.1.

Vendor: uixthemes
Product: Motta Addons
Published: Mar 25, 2026
Source: NVD
CVE-2026-25026 HIGH - 7.5

Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11.

Vendor: RadiusTheme
Product: Team
Published: Mar 25, 2026
Source: NVD
CVE-2026-25025 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5.2.

Vendor: e4jvikwp
Product: VikRestaurants
Published: Mar 25, 2026
Source: NVD
CVE-2026-25018 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects NaturaLife Extensions: from n/a through <= 2.1.

Vendor: stmcan
Product: NaturaLife Extensions
Published: Mar 25, 2026
Source: NVD
CVE-2026-25017 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows PHP Local File Inclusion.This issue affects NaturaLife Extensions: from n/a through <= 2.1.

Vendor: stmcan
Product: NaturaLife Extensions
Published: Mar 25, 2026
Source: NVD
CVE-2026-25013 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a through <= 2.0.8.

Vendor: WHMCSdes
Product: Phox Hosting
Published: Mar 25, 2026
Source: NVD
CVE-2026-25007 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Blind SQL Injection.This issue affects ElementInvader Addons for Elementor: from n/a through ...

Vendor: Element Invader
Product: ElementInvader Addons for Elementor
Published: Mar 25, 2026
Source: NVD
CVE-2026-25002 HIGH - 7.5

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress &#8211; Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress &#8211; Sepay Payment: from n/a through <= 4.0.0.

Vendor: ThimPress
Product: LearnPress &#8211; Sepay Payment
Published: Mar 25, 2026
Source: NVD
CVE-2026-25001 HIGH - 8.5

Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12.

Vendor: Saad Iqbal
Product: Post Snippets
Published: Mar 25, 2026
Source: NVD
CVE-2026-24983 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from n/a through <= 8.41.

Vendor: UpSolution
Product: UpSolution Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-24981 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.

Vendor: NooTheme
Product: Visionary Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-24980 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue affects Visionary Core: from n/a through <= 1.4.9.

Vendor: NooTheme
Product: Visionary Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-24979 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobica Core: from n/a through <= 1.4.1.

Vendor: NooTheme
Product: Jobica Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-24978 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1.

Vendor: NooTheme
Product: Jobica Core
Published: Mar 25, 2026
Source: NVD
CVE-2026-24977 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Organici Library: from n/a through <= 2.1.2.

Vendor: NooTheme
Product: Organici Library
Published: Mar 25, 2026
Source: NVD
CVE-2026-24976 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.

Vendor: NooTheme
Product: Organici Library
Published: Mar 25, 2026
Source: NVD
CVE-2026-24975 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici Library: from n/a through <= 2.1.2.

Vendor: NooTheme
Product: Organici Library
Published: Mar 25, 2026
Source: NVD