Total CVEs

138,196

Critical Severity

3,545

High Severity

12,691

Last 7 Days

1,978
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 161 - 180 of 34,601 CVEs
CVE-2026-28573 MEDIUM - 5.5

In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Vendor: Google
Product: Android
Published: Jun 18, 2026
Source: NVD
CVE-2026-12137 MEDIUM - 6.1

The SysBasics Customize My Account for WooCommerce โ€“ Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 4.3.6 due to insufficient input sanitization and output es...

Vendor: phppoet
Product: SysBasics Customize My Account for WooCommerce โ€“ Dashboard, Endpoints, Avatar & Menu Manager
Published: Jun 18, 2026
Source: NVD
CVE-2026-12136 MEDIUM - 6.4

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcode in versions up to, and including, 4.3.6. This is due to insufficient input sanitization and output escaping on user supplied attributes (min_...

Vendor: phppoet
Product: SysBasics Customize My Account for WooCommerce โ€“ Dashboard, Endpoints, Avatar & Menu Manager
Published: Jun 18, 2026
Source: NVD
CVE-2026-12111 MEDIUM - 4.3

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable ...

Vendor: codepeople
Product: Appointment Booking Calendar
Published: Jun 18, 2026
Source: NVD

The UsersWP โ€“ Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the 'user_id' parameter due to missing validation on a user cont...

Vendor: stiofansisland
Product: UsersWP โ€“ Front-end login form, User Registration, User Profile & Members Directory plugin for WP
Published: Jun 18, 2026
Source: NVD
CVE-2026-12098 MEDIUM - 6.4

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all versions up to, and including, 11.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

Vendor: blubrry
Product: PowerPress Podcasting plugin by Blubrry
Published: Jun 18, 2026
Source: NVD
CVE-2026-11395 HIGH - 7.2

The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.0 via the pull_the_trigger. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be ...

Vendor: mariovalney
Product: CF7 to Webhook
Published: Jun 18, 2026
Source: NVD
CVE-2026-9860 HIGH - 8.8

The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.2 via the 'account-id' parameter parameter. This is due to insufficient privilege enforcement on the cf_images_do_setup AJAX handler,...

Published: Jun 18, 2026
Source: NVD
CVE-2026-9199 MEDIUM - 4.3

The Equalize Digital Accessibility Checker โ€“ WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes ...

Published: Jun 18, 2026
Source: NVD
CVE-2026-55740 CRITICAL - 9.8

Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL query (select * from bus_info where id=$busid...

Vendor: Nur-Alam39
Product: bus-ticket
Published: Jun 18, 2026
Source: NVD
CVE-2026-12120 MEDIUM - 5.3

The FireBox Popups โ€“ Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.7 via the 'form_id' parameter. This makes it possible for unauthenticated attackers to extract download a full CSV exp...

Vendor: fireplugins
Product: FireBox Popups โ€“ Increase Sales and Grow Your Email List
Published: Jun 18, 2026
Source: NVD
CVE-2026-12093 MEDIUM - 5.3

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary ...

Vendor: wpinsider-1
Product: Simple Membership
Published: Jun 18, 2026
Source: NVD
CVE-2026-11784 MEDIUM - 4.3

The Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This ma...

Vendor: optimole
Product: Optimole โ€“ Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
Published: Jun 18, 2026
Source: NVD
CVE-2026-11777 MEDIUM - 4.9

The Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficie...

Vendor: 10web
Product: Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-11776 MEDIUM - 4.9

The Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of suff...

Vendor: 10web
Product: Form Maker by 10Web โ€“ Mobile-Friendly Drag & Drop Contact Form Builder
Published: Jun 18, 2026
Source: NVD
CVE-2026-11402 MEDIUM - 6.4

The Services Section Block โ€“ Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'link' Block Attribute in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possib...

Vendor: bplugins
Product: Services Section Block โ€“ Showcase Service Details in Grid or Columns
Published: Jun 18, 2026
Source: NVD
CVE-2026-11360 MEDIUM - 4.9

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_direction' parameter in all versions up to, and including, 4.0.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existi...

Vendor: algolplus
Product: Advanced Order Export For WooCommerce
Published: Jun 18, 2026
Source: NVD
CVE-2026-11358 MEDIUM - 4.4

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.6 due to insufficient input sanitization and output escaping. This makes it po...

Vendor: themeisle
Product: Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More
Published: Jun 18, 2026
Source: NVD
CVE-2026-11357 MEDIUM - 4.3

The Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above...

Vendor: stellarwp
Product: Kadence Blocks โ€” Page Builder Toolkit for Gutenberg Editor
Published: Jun 18, 2026
Source: NVD
CVE-2026-10736 MEDIUM - 4.9

The Tutor LMS โ€“ eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the exist...

Vendor: themeum
Product: Tutor LMS โ€“ eLearning and online course solution
Published: Jun 18, 2026
Source: NVD