Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High1
Medium1
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-08-10

CVE-2026-16558 - Ymc Filter Plugin

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and does not verify object ownership when the setting is saved, allowing users with the Contributor role and above to store JavaScript that executes in the browser of any visitor viewing an affected filter.

PLUGIN Ymc Filter

CVE-2026-16558

MEDIUM CVSS 5.4 2026-08-08
Threat Entry Updated 2026-08-08

CVE-2026-16559 - Ymc Filter Plugin

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload by low-privileged users, allowing users with the Author role and above to upload a file containing JavaScript that executes in the site's origin when the file is viewed.

PLUGIN Ymc Filter

CVE-2026-16559

UNKNOWN CVSS 0.0 2026-08-08
Threat Entry Updated 2026-06-26

CVE-2026-10823 - Ymc Filter Plugin

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.

PLUGIN Ymc Filter

CVE-2026-10823

HIGH CVSS 7.5 2026-06-26
Scroll to top