Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total5
Critical0
High1
Medium4
Reset
Showing 1-5 of 5 records
Threat Entry Updated 2026-04-14

CVE-2026-4338 - Activitypub Plugin

The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts

PLUGIN Activitypub

CVE-2026-4338

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2024-11-21

CVE-2023-5057 - Activitypub Plugin

The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks

PLUGIN Activitypub

CVE-2023-5057

MEDIUM CVSS 5.4 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-3746 - Activitypub Plugin

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

PLUGIN Activitypub

CVE-2023-3746

MEDIUM CVSS 5.4 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-3707 - Activitypub Plugin

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected by this issue.

PLUGIN Activitypub

CVE-2023-3707

MEDIUM CVSS 4.3 2023-10-16
Threat Entry Updated 2025-04-23

CVE-2023-3706 - Activitypub Plugin

The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector

PLUGIN Activitypub

CVE-2023-3706

MEDIUM CVSS 4.3 2023-10-16
Scroll to top