Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,238
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1 - 20 of 2,483 CVEs
CVE-2026-2312 MEDIUM - 4.3

The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_image() functions due to missing validation on a user controlled key. This makes it possible for auth...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1512 MEDIUM - 6.4

The Essential Addons for Elementor โ€“ Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Info Box widget in all versions up to, and including, 6.5.9 due to insufficient input sanitization and output escaping on user suppli...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1258 MEDIUM - 4.9

The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map' API endpoints in all versions up to, and including, 1.19.2 . This is due to insufficient escaping on th...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1254 MEDIUM - 4.3

The Modula Image Gallery โ€“ Photo Grid & Video Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.13.6. This is due to the plugin not properly verifying that a user is authorized to modify specific posts before updating them via the REST API...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1249 MEDIUM - 5.0

The MP3 Audio Player โ€“ Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and...

Published: Feb 14, 2026
Source: NVD
CVE-2026-0550 MEDIUM - 6.4

The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' shortcode in all versions up to, and including, 2.9.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

Published: Feb 14, 2026
Source: NVD
CVE-2026-2022 MEDIUM - 4.3

The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99. This makes it possible for authenticated attackers, with Subscriber-level ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1987 MEDIUM - 5.4

The Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` function lacking proper authorization checks and ownership verification when updating events. This makes it...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1985 MEDIUM - 6.4

The Press3D plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 3D Model Gutenberg block in all versions up to, and including, 1.0.2. This is due to the plugin failing to sanitize and validate the URL scheme when storing link URLs for 3D model blocks, allowing `javascript:` URL...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1944 MEDIUM - 5.3

The CallbackKiller service widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cbk_save() function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to modify the plugin's site ID s...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1939 MEDIUM - 6.4

The Percent to Infograph plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `percent_to_graph` shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1915 MEDIUM - 6.4

The Simple Plyr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'poster' parameter in the 'plyr' shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1910 MEDIUM - 6.4

The UpMenu โ€“ Online ordering for restaurants plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lang' attribute of the 'upmenu-menu' shortcode in all versions up to, and including, 3.1. This is due to insufficient input sanitization and output escaping on ...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1905 MEDIUM - 6.4

The Sphere Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter in the 'show_sphere_image' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for a...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1903 MEDIUM - 6.4

The Ravelry Designs Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout' attribute of the 'sb_ravelry_designs' shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sanitization and output escaping on user su...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1901 MEDIUM - 6.4

The QuestionPro Surveys plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'questionpro' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1796 MEDIUM - 6.1

The StyleBidet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1795 MEDIUM - 6.1

The Address Bar Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL Path in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1792 MEDIUM - 6.1

The Geo Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL path in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w...

Published: Feb 14, 2026
Source: NVD
CVE-2026-1394 MEDIUM - 4.3

The WP Quick Contact Us plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings ...

Published: Feb 14, 2026
Source: NVD