Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,636
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,721 - 10,740 of 13,241 CVEs
CVE-2025-69378 HIGH - 7.3

Incorrect Privilege Assignment vulnerability in XforWooCommerce Product Filter for WooCommerce prdctfltr allows Privilege Escalation.This issue affects Product Filter for WooCommerce: from n/a through <= 9.1.2.

Vendor: XforWooCommerce
Product: Product Filter for WooCommerce
Published: Feb 20, 2026
Source: NVD
CVE-2025-69377 HIGH - 7.7

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0.

Vendor: vanquish
Product: User Extra Fields
Published: Feb 20, 2026
Source: NVD
CVE-2025-69376 HIGH - 8.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Path Traversal.This issue affects User Extra Fields: from n/a through <= 17.0.

Vendor: vanquish
Product: User Extra Fields
Published: Feb 20, 2026
Source: NVD
CVE-2025-69375 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Portfolio Builder swp-portfolio allows PHP Local File Inclusion.This issue affects Portfolio Builder: from n/a through <= 1.2.5.

Vendor: SolverWp
Product: Portfolio Builder
Published: Feb 20, 2026
Source: NVD
CVE-2025-69374 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Eleblog โ€“ Elementor Blog And Magazine Addons ele-blog allows PHP Local File Inclusion.This issue affects Eleblog โ€“ Elementor Blog And Magazine Addons: from n/a ...

Vendor: SolverWp
Product: Eleblog โ€“ Elementor Blog And Magazine Addons
Published: Feb 20, 2026
Source: NVD
CVE-2025-69373 HIGH - 7.5

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in beeteam368 VidoRev vidorev allows PHP Local File Inclusion.This issue affects VidoRev: from n/a through <= 2.9.9.9.9.9.7.

Vendor: beeteam368
Product: VidoRev
Published: Feb 20, 2026
Source: NVD
CVE-2025-69368 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes SOHO - Photography WordPress Theme soho allows DOM-Based XSS.This issue affects SOHO - Photography WordPress Theme: from n/a through <= 3.0.3.

Vendor: GT3themes
Product: SOHO - Photography WordPress Theme
Published: Feb 20, 2026
Source: NVD
CVE-2025-69367 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyster - Photography WordPress Theme: from n/a through <= 4.4.3.

Vendor: GT3themes
Product: Oyster - Photography WordPress Theme
Published: Feb 20, 2026
Source: NVD
CVE-2025-69330 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Prestige prestige allows Reflected XSS.This issue affects Prestige: from n/a through < 1.4.1.

Vendor: Jthemes
Product: Prestige
Published: Feb 20, 2026
Source: NVD
CVE-2025-69328 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.

Vendor: magepeopleteam
Product: Booking and Rental Manager
Published: Feb 20, 2026
Source: NVD
CVE-2025-69326 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.

Vendor: Basix
Product: NEX-Forms
Published: Feb 20, 2026
Source: NVD
CVE-2025-69324 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.

Vendor: Basix
Product: NEX-Forms
Published: Feb 20, 2026
Source: NVD
CVE-2025-69323 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs Slimstat Analytics wp-slimstat allows Reflected XSS.This issue affects Slimstat Analytics: from n/a through <= 5.3.2.

Vendor: VeronaLabs
Product: Slimstat Analytics
Published: Feb 20, 2026
Source: NVD
CVE-2025-69322 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes PeakShops peakshops allows PHP Local File Inclusion.This issue affects PeakShops: from n/a through < 1.5.9.

Vendor: fuelthemes
Product: PeakShops
Published: Feb 20, 2026
Source: NVD
CVE-2025-69303 HIGH - 7.5

Missing Authorization vulnerability in modeltheme ModelTheme Framework modeltheme-framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ModelTheme Framework: from n/a through <= 1.9.2.

Vendor: modeltheme
Product: ModelTheme Framework
Published: Feb 20, 2026
Source: NVD
CVE-2025-69302 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core Features designthemes-core-features allows Reflected XSS.This issue affects DesignThemes Core Features: from n/a through <= 2.3.

Vendor: designthemes
Product: DesignThemes Core Features
Published: Feb 20, 2026
Source: NVD
CVE-2025-69299 HIGH - 7.2

Server-Side Request Forgery (SSRF) vulnerability in Laborator Oxygen oxygen allows Server Side Request Forgery.This issue affects Oxygen: from n/a through <= 6.0.8.

Vendor: Laborator
Product: Oxygen
Published: Feb 20, 2026
Source: NVD
CVE-2025-69298 HIGH - 7.5

Missing Authorization vulnerability in GhostPool Gauge gauge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gauge: from n/a through <= 6.56.4.

Vendor: GhostPool
Product: Gauge
Published: Feb 20, 2026
Source: NVD
CVE-2025-69297 HIGH - 7.5

Missing Authorization vulnerability in GhostPool Aardvark Plugin aardvark-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aardvark Plugin: from n/a through <= 2.19.

Vendor: GhostPool
Product: Aardvark Plugin
Published: Feb 20, 2026
Source: NVD
CVE-2025-69296 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhostPool Aardvark aardvark allows Reflected XSS.This issue affects Aardvark: from n/a through <= 4.6.3.

Vendor: GhostPool
Product: Aardvark
Published: Feb 20, 2026
Source: NVD