Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,607
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 10,761 - 10,780 of 13,241 CVEs
CVE-2025-68531 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Object Injection.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6.

Vendor: modeltheme
Product: ModelTheme Addons for WPBakery and Elementor
Published: Feb 20, 2026
Source: NVD
CVE-2025-68526 HIGH - 8.8

Deserialization of Untrusted Data vulnerability in A WP Life Modal Popup Box modal-popup-box allows Object Injection.This issue affects Modal Popup Box: from n/a through <= 1.6.1.

Vendor: A WP Life
Product: Modal Popup Box
Published: Feb 20, 2026
Source: NVD
CVE-2025-68501 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mollie Mollie Payments for WooCommerce mollie-payments-for-woocommerce allows Reflected XSS.This issue affects Mollie Payments for WooCommerce: from n/a through <= 8.1.1.

Vendor: Mollie
Product: Mollie Payments for WooCommerce
Published: Feb 20, 2026
Source: NVD
CVE-2025-68495 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.

Vendor: Crocoblock
Product: JetEngine
Published: Feb 20, 2026
Source: NVD
CVE-2025-68069 HIGH - 7.1

Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10.

Vendor: wpWax
Product: Directorist
Published: Feb 20, 2026
Source: NVD
CVE-2025-68051 HIGH - 7.4

Authorization Bypass Through User-Controlled Key vulnerability in Shiprocket Shiprocket shiprocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shiprocket: from n/a through <= 2.0.8.

Vendor: Shiprocket
Product: Shiprocket
Published: Feb 20, 2026
Source: NVD
CVE-2025-68048 HIGH - 7.5

Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0.

Vendor: XLPlugins
Product: NextMove Lite
Published: Feb 20, 2026
Source: NVD
CVE-2025-68043 HIGH - 7.3

Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LottieFiles: from n/a through <= 3.0.0.

Vendor: LottieFiles
Product: LottieFiles
Published: Feb 20, 2026
Source: NVD
CVE-2025-68037 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atlas Gondal Export Media URLs export-media-urls allows Reflected XSS.This issue affects Export Media URLs: from n/a through <= 2.2.

Vendor: Atlas Gondal
Product: Export Media URLs
Published: Feb 20, 2026
Source: NVD
CVE-2025-68031 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in faraz sms افزونه پیامک حرفه ای فراز اس ام اس farazsms allows Reflected XSS.This issue affects افزونه پیامک حرفه ای فراز اس ام اس: from n/a through <= 2.7.3.

Vendor: faraz sms
Product: افزونه پیامک حرفه ای فراز اس ام اس
Published: Feb 20, 2026
Source: NVD
CVE-2025-67998 HIGH - 8.8

Authentication Bypass Using an Alternate Path or Channel vulnerability in kamleshyadav Miraculous Elementor miraculous-el allows Authentication Abuse.This issue affects Miraculous Elementor: from n/a through <= 2.0.7.

Vendor: kamleshyadav
Product: Miraculous Elementor
Published: Feb 20, 2026
Source: NVD
CVE-2025-67994 HIGH - 7.5

Missing Authorization vulnerability in YayCommerce YayCurrency yaycurrency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayCurrency: from n/a through <= 3.3.

Vendor: YayCommerce
Product: YayCurrency
Published: Feb 20, 2026
Source: NVD
CVE-2025-67992 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean PatioTime patiotime allows PHP Local File Inclusion.This issue affects PatioTime: from n/a through < 2.1.

Vendor: LoftOcean
Product: PatioTime
Published: Feb 20, 2026
Source: NVD
CVE-2025-67991 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vanquish User Extra Fields wp-user-extra-fields allows Reflected XSS.This issue affects User Extra Fields: from n/a through <= 16.8.

Vendor: vanquish
Product: User Extra Fields
Published: Feb 20, 2026
Source: NVD
CVE-2025-67990 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 GMap Targeting gmap-targeting allows Reflected XSS.This issue affects GMap Targeting: from n/a through <= 1.1.7.

Vendor: RealMag777
Product: GMap Targeting
Published: Feb 20, 2026
Source: NVD
CVE-2025-67988 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean CozyStay cozystay allows PHP Local File Inclusion.This issue affects CozyStay: from n/a through < 1.9.1.

Vendor: LoftOcean
Product: CozyStay
Published: Feb 20, 2026
Source: NVD
CVE-2025-67987 HIGH - 8.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows SQL Injection.This issue affects Quiz And Survey Master: from n/a through <= 10.3.1.

Vendor: ExpressTech Systems
Product: Quiz And Survey Master
Published: Feb 20, 2026
Source: NVD
CVE-2025-67984 HIGH - 7.1

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in calliko NPS computy nps-computy allows DOM-Based XSS.This issue affects NPS computy: from n/a through <= 2.8.2.

Vendor: calliko
Product: NPS computy
Published: Feb 20, 2026
Source: NVD
CVE-2025-67982 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Urna urna allows PHP Local File Inclusion.This issue affects Urna: from n/a through <= 2.5.12.

Vendor: thembay
Product: Urna
Published: Feb 20, 2026
Source: NVD
CVE-2025-67981 HIGH - 8.1

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.

Vendor: thembay
Product: Besa
Published: Feb 20, 2026
Source: NVD