Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,638
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 11,881 - 11,900 of 36,815 CVEs
CVE-2026-6710 MEDIUM - 4.3

The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the SkysaApps_Admin_AppPage function. This makes it possible for unauthenticated attackers to trick a site adm...

Published: May 12, 2026
Source: NVD
CVE-2026-6709 MEDIUM - 4.3

The Coinbase Commerce for Contact Form 7 plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.1.2. This is due to a missing capability check and missing nonce verification in the save_settings() function, which is registered on the admin_post_cccf7_save_setti...

Published: May 12, 2026
Source: NVD
CVE-2026-6708 MEDIUM - 5.3

The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered with a permission_callback of '__return_true', which b...

Published: May 12, 2026
Source: NVD
CVE-2026-6690 HIGH - 7.2

The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the `wp_ajax_nopriv_lp_update_mds` action being registered without nonce verification or capabi...

Published: May 12, 2026
Source: NVD
CVE-2026-6663 MEDIUM - 4.8

The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints (gwd-backup.php and gwd-logs.php) not verifying authentication when the API key has not been co...

Published: May 12, 2026
Source: NVD
CVE-2026-6402 MEDIUM - 5.3

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustwort...

Vendor: npm
Product: webpack-dev-server
Published: May 12, 2026
Source: NVD
CVE-2026-6256 MEDIUM - 6.4

The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

Published: May 12, 2026
Source: NVD
CVE-2026-6247 MEDIUM - 6.4

The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attribut...

Published: May 12, 2026
Source: NVD
CVE-2026-6237 MEDIUM - 6.4

The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

Published: May 12, 2026
Source: NVD
CVE-2026-5715 MEDIUM - 6.4

The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This mak...

Published: May 12, 2026
Source: NVD
CVE-2026-5693 MEDIUM - 5.3

The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) ins...

Published: May 12, 2026
Source: NVD
CVE-2026-5340 MEDIUM - 6.4

The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up to, and including, 9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

Published: May 12, 2026
Source: NVD
CVE-2026-5028 MEDIUM - 6.5

The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and including, 1.2.6. This is due to insufficient escaping on the user supplied parameter and lack of...

Published: May 12, 2026
Source: NVD
CVE-2026-4920 MEDIUM - 6.4

The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

Published: May 12, 2026
Source: NVD
CVE-2026-4859 MEDIUM - 6.4

The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authen...

Published: May 12, 2026
Source: NVD
CVE-2026-4663 MEDIUM - 5.3

The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin exposing a REST API endpoint /wp-json/ipospays/v1/save_settings with 'permission_callback' set to '__return_true', which allows un...

Published: May 12, 2026
Source: NVD
CVE-2026-4301 MEDIUM - 4.3

The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() ...

Published: May 12, 2026
Source: NVD
CVE-2026-3604 MEDIUM - 4.9

The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

Published: May 12, 2026
Source: NVD
CVE-2026-39432 HIGH - 8.2

Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.

Vendor: Arraytics
Product: Timetics
Published: May 12, 2026
Source: NVD
CVE-2026-2993 HIGH - 7.5

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This ma...

Published: May 12, 2026
Source: NVD