Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,636
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,701 - 10,720 of 13,241 CVEs
CVE-2025-69401 HIGH - 7.5

Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2.

Vendor: mdalabar
Product: WooODT Lite
Published: Feb 20, 2026
Source: NVD
CVE-2025-69400 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Yokoo yokoo allows PHP Local File Inclusion.This issue affects Yokoo: from n/a through <= 1.1.11.

Vendor: ThemeREX
Product: Yokoo
Published: Feb 20, 2026
Source: NVD
CVE-2025-69399 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Cobble cobble allows PHP Local File Inclusion.This issue affects Cobble: from n/a through <= 1.7.

Vendor: ThemeREX
Product: Cobble
Published: Feb 20, 2026
Source: NVD
CVE-2025-69398 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Plank plank allows PHP Local File Inclusion.This issue affects Plank: from n/a through <= 1.7.

Vendor: ThemeREX
Product: Plank
Published: Feb 20, 2026
Source: NVD
CVE-2025-69397 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tint tint allows PHP Local File Inclusion.This issue affects Tint: from n/a through <= 1.7.

Vendor: ThemeREX
Product: Tint
Published: Feb 20, 2026
Source: NVD
CVE-2025-69396 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Splendour splendour allows PHP Local File Inclusion.This issue affects Splendour: from n/a through <= 1.23.

Vendor: ThemeREX
Product: Splendour
Published: Feb 20, 2026
Source: NVD
CVE-2025-69395 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gable gable allows PHP Local File Inclusion.This issue affects Gable: from n/a through <= 1.5.

Vendor: ThemeREX
Product: Gable
Published: Feb 20, 2026
Source: NVD
CVE-2025-69394 HIGH - 7.5

Authorization Bypass Through User-Controlled Key vulnerability in cnvrse Cnvrse cnvrse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cnvrse: from n/a through <= 026.02.10.20.

Vendor: cnvrse
Product: Cnvrse
Published: Feb 20, 2026
Source: NVD
CVE-2025-69393 HIGH - 7.5

Missing Authorization vulnerability in Jthemes Exzo exzo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Exzo: from n/a through <= 1.2.4.

Vendor: Jthemes
Product: Exzo
Published: Feb 20, 2026
Source: NVD
CVE-2025-69392 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itex iMoney imoney allows Reflected XSS.This issue affects iMoney: from n/a through <= 0.36.

Vendor: itex
Product: iMoney
Published: Feb 20, 2026
Source: NVD
CVE-2025-69391 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Diamond diamond allows Reflected XSS.This issue affects Diamond: from n/a through <= 2.4.8.

Vendor: GT3themes
Product: Diamond
Published: Feb 20, 2026
Source: NVD
CVE-2025-69390 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Business Template Blocks for WPBakery (Visual Composer) Page Builder templates-and-addons-for-wpbakery-page-builder allows Reflected XSS.This issue affects Business Template Block...

Vendor: themebon
Product: Business Template Blocks for WPBakery (Visual Composer) Page Builder
Published: Feb 20, 2026
Source: NVD
CVE-2025-69389 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Visitor Maps Extended Referer Field visitor-maps-extended-referer-field allows Reflected XSS.This issue affects Visitor Maps Extended Referer Field: from n/a through <= 1.2....

Vendor: Hugh Mungus
Product: Visitor Maps Extended Referer Field
Published: Feb 20, 2026
Source: NVD
CVE-2025-69387 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in whatwouldjessedo Simple Retail Menus simple-retail-menus allows PHP Local File Inclusion.This issue affects Simple Retail Menus: from n/a through <= 4.2.1.

Vendor: whatwouldjessedo
Product: Simple Retail Menus
Published: Feb 20, 2026
Source: NVD
CVE-2025-69386 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realvirtualmx RVCFDI para Woocommerce rvcfdi-para-woocommerce allows Reflected XSS.This issue affects RVCFDI para Woocommerce: from n/a through <= 8.1.8.

Vendor: realvirtualmx
Product: RVCFDI para Woocommerce
Published: Feb 20, 2026
Source: NVD
CVE-2025-69384 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdiscover Timeline Event History timeline-event-history allows Reflected XSS.This issue affects Timeline Event History: from n/a through <= 3.2.

Vendor: wpdiscover
Product: Timeline Event History
Published: Feb 20, 2026
Source: NVD
CVE-2025-69383 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows PHP Local File Inclusion.This issue affects WP shop: from n/a through <= 2.6.1.

Vendor: Agence web Eoxia - Montpellier
Product: WP shop
Published: Feb 20, 2026
Source: NVD
CVE-2025-69381 HIGH - 7.1

Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Product Editor: from n/a through <= 3.0.

Vendor: vanquish
Product: WooCommerce Bulk Product Editor
Published: Feb 20, 2026
Source: NVD
CVE-2025-69380 HIGH - 7.5

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8.

Vendor: vanquish
Product: Upload Files Anywhere
Published: Feb 20, 2026
Source: NVD
CVE-2025-69379 HIGH - 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8.

Vendor: vanquish
Product: Upload Files Anywhere
Published: Feb 20, 2026
Source: NVD