Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1,249
Critical1,249
High0
Medium0
Reset
Showing 341-360 of 1249 records
Threat Entry Updated 2026-06-17

CVE-2026-27439 - Dentario Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects Dentario: from n/a through

PLUGIN Dentario

CVE-2026-27439

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27438 - Kingler Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects Kingler: from n/a through

PLUGIN Kingler

CVE-2026-27438

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27437 - Tennis Club Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This issue affects Tennis Club: from n/a through

PLUGIN Tennis Club

CVE-2026-27437

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27417 - Sweet Date Plugin

Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue affects Sweet Date: from n/a through < 4.0.1.

PLUGIN Sweet Date

CVE-2026-27417

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27389 - WeDesignTech Ultimate Booking Addon Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through

PLUGIN WeDesignTech Ultimate Booking Addon

CVE-2026-27389

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27384 - W3 Total Cache Plugin

Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through

PLUGIN W3 Total Cache

CVE-2026-27384

CRITICAL CVSS 9.0 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-24960 - Charety Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.

PLUGIN Charety

CVE-2026-24960

CRITICAL CVSS 9.9 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-23802 - AI Engine Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through

PLUGIN AI Engine

CVE-2026-23802

CRITICAL CVSS 9.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22501 - Mounthood Plugin

Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through

PLUGIN Mounthood

CVE-2026-22501

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22497 - Jardi Plugin

Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through

PLUGIN Jardi

CVE-2026-22497

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22475 - Estate Plugin

Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through

PLUGIN Estate

CVE-2026-22475

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22474 - Equestrian Centre Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through

PLUGIN Equestrian Centre

CVE-2026-22474

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22454 - Solaris Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through

PLUGIN Solaris

CVE-2026-22454

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22453 - Pets Club Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through

PLUGIN Pets Club

CVE-2026-22453

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22451 - Handyman Plugin

Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through

PLUGIN Handyman

CVE-2026-22451

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22417 - Grand Wedding Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Wedding grandwedding allows Object Injection.This issue affects Grand Wedding: from n/a through < 3.1.11.

PLUGIN Grand Wedding

CVE-2026-22417

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22390 - Builderall Builder for WordPress Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Code Injection.This issue affects Builderall Builder for WordPress: from n/a through

PLUGIN Builderall Builder for WordPress

CVE-2026-22390

CRITICAL CVSS 9.9 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-1492 - User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Plugin

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

PLUGIN User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-1492

CRITICAL CVSS 9.8 2026-03-03
Threat Entry Updated 2026-06-17

CVE-2026-2628 - Azure Ad Sso Login Plugin

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.

PLUGIN Azure Ad Sso Login

CVE-2026-2628

CRITICAL CVSS 9.8 2026-03-03
Threat Entry Updated 2026-06-17

CVE-2026-2251 - Xerox FreeFlow Core Plugin

Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads https://www.support.xerox.com/en-us/product/core/downloads

PLUGIN Xerox FreeFlow Core

CVE-2026-2251

CRITICAL CVSS 9.8 2026-02-27
Scroll to top