Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,775
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,761 - 9,780 of 13,224 CVEs
CVE-2026-28125 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Midi midi allows PHP Local File Inclusion.This issue affects Midi: from n/a through <= 1.14.

Vendor: AncoraThemes
Product: Midi
Published: Mar 05, 2026
Source: NVD
CVE-2026-28124 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Notarius notarius allows PHP Local File Inclusion.This issue affects Notarius: from n/a through <= 1.9.

Vendor: AncoraThemes
Product: Notarius
Published: Mar 05, 2026
Source: NVD
CVE-2026-28123 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Veil veil allows PHP Local File Inclusion.This issue affects Veil: from n/a through <= 1.9.

Vendor: AncoraThemes
Product: Veil
Published: Mar 05, 2026
Source: NVD
CVE-2026-28122 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CridioStudio ListingPro listingpro-plugin allows Reflected XSS.This issue affects ListingPro: from n/a through <= 2.9.8.

Vendor: CridioStudio
Product: ListingPro
Published: Mar 05, 2026
Source: NVD
CVE-2026-28121 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Anderson andersonclinic allows PHP Local File Inclusion.This issue affects Anderson: from n/a through <= 1.4.2.

Vendor: AncoraThemes
Product: Anderson
Published: Mar 05, 2026
Source: NVD
CVE-2026-28120 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dr.Patterson dr-patterson allows PHP Local File Inclusion.This issue affects Dr.Patterson: from n/a through <= 1.3.2.

Vendor: ThemeREX
Product: Dr.Patterson
Published: Mar 05, 2026
Source: NVD
CVE-2026-28119 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Nirvana nirvana allows PHP Local File Inclusion.This issue affects Nirvana: from n/a through <= 2.6.

Vendor: axiomthemes
Product: Nirvana
Published: Mar 05, 2026
Source: NVD
CVE-2026-28118 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Welldone welldone allows PHP Local File Inclusion.This issue affects Welldone: from n/a through <= 2.4.

Vendor: axiomthemes
Product: Welldone
Published: Mar 05, 2026
Source: NVD
CVE-2026-28117 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.9.

Vendor: axiomthemes
Product: smart SEO
Published: Mar 05, 2026
Source: NVD
CVE-2026-28113 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Reflected XSS.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.1.

Vendor: azzaroco
Product: Ultimate Learning Pro
Published: Mar 05, 2026
Source: NVD
CVE-2026-28112 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup AllInOne - Banner Rotator all-in-one-bannerRotator allows Reflected XSS.This issue affects AllInOne - Banner Rotator: from n/a through <= 3.8.

Vendor: LambertGroup
Product: AllInOne - Banner Rotator
Published: Mar 05, 2026
Source: NVD
CVE-2026-28110 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Playlist all-in-one-bannerWithPlaylist allows Reflected XSS.This issue affects LambertGroup - AllInOne - Banner with Playlist: from n/a t...

Vendor: LambertGroup
Product: LambertGroup - AllInOne - Banner with Playlist
Published: Mar 05, 2026
Source: NVD
CVE-2026-28109 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Content Slider all-in-one-contentSlider allows Reflected XSS.This issue affects LambertGroup - AllInOne - Content Slider: from n/a through <= 3.8.

Vendor: LambertGroup
Product: LambertGroup - AllInOne - Content Slider
Published: Mar 05, 2026
Source: NVD
CVE-2026-28108 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LambertGroup - AllInOne - Banner with Thumbnails all-in-one-thumbnailsBanner allows Reflected XSS.This issue affects LambertGroup - AllInOne - Banner with Thumbnails: from n/a...

Vendor: LambertGroup
Product: LambertGroup - AllInOne - Banner with Thumbnails
Published: Mar 05, 2026
Source: NVD
CVE-2026-28107 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Muzicon muzicon allows PHP Local File Inclusion.This issue affects Muzicon: from n/a through <= 1.9.0.

Vendor: ThemeREX
Product: Muzicon
Published: Mar 05, 2026
Source: NVD
CVE-2026-28103 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup LBG Zoominoutslider lbg_zoominoutslider allows Reflected XSS.This issue affects LBG Zoominoutslider: from n/a through <= 5.4.5.

Vendor: LambertGroup
Product: LBG Zoominoutslider
Published: Mar 05, 2026
Source: NVD
CVE-2026-28102 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Classic uberSlider_classic allows Reflected XSS.This issue affects UberSlider Classic: from n/a through <= 2.5.

Vendor: LambertGroup
Product: UberSlider Classic
Published: Mar 05, 2026
Source: NVD
CVE-2026-28101 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider MouseInteraction uberSlider_mouseinteraction allows Reflected XSS.This issue affects UberSlider MouseInteraction: from n/a through <= 2.3.

Vendor: LambertGroup
Product: UberSlider MouseInteraction
Published: Mar 05, 2026
Source: NVD
CVE-2026-28100 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider PerpetuumMobile uberSlider_perpetuummobile allows Reflected XSS.This issue affects UberSlider PerpetuumMobile: from n/a through <= 2.3.

Vendor: LambertGroup
Product: UberSlider PerpetuumMobile
Published: Mar 05, 2026
Source: NVD
CVE-2026-28099 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup UberSlider Ultra uberSlider_ultra allows Reflected XSS.This issue affects UberSlider Ultra: from n/a through <= 2.3.

Vendor: LambertGroup
Product: UberSlider Ultra
Published: Mar 05, 2026
Source: NVD