Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-49774 - RD Station Plugin
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
CVE-2026-49774
CVE-2026-49772 - The Events Calendar Plugin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
CVE-2026-49772
CVE-2026-39574 - WordPress component
Unauthenticated SQL Injection in InPost Gallery
CVE-2026-39574
CVE-2026-9691 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
CVE-2026-9691
CVE-2026-52703 - WordPress component
Unauthenticated Path Traversal in FastDup
CVE-2026-52703
CVE-2026-52693 - WordPress component
Unauthenticated SQL Injection in eCommerce Product Catalog
CVE-2026-52693
CVE-2026-49781 - WordPress component
Unauthenticated PHP Object Injection in OttoKit
CVE-2026-49781
CVE-2026-49770 - WordPress component
Unauthenticated PHP Object Injection in WP Travel Engine
CVE-2026-49770
CVE-2026-49776 - WordPress component
Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites
CVE-2026-49776
CVE-2026-49766 - WordPress component
Subscriber Arbitrary File Deletion in WP User Manager
CVE-2026-49766
CVE-2026-49769 - WordPress component
Unauthenticated PHP Object Injection in wpForo Forum
CVE-2026-49769
CVE-2026-49768 - WordPress component
Unauthenticated PHP Object Injection in Happyforms
CVE-2026-49768
CVE-2026-49765 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
CVE-2026-49765
CVE-2026-49764 - WordPress component
Unauthenticated Broken Authentication in RegistrationMagic
CVE-2026-49764
CVE-2026-49763 - Integration for Contact Form 7 HubSpot Plugin
Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot
CVE-2026-49763
CVE-2026-49109 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
CVE-2026-49109
CVE-2026-49106 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact
CVE-2026-49106
CVE-2026-49105 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
CVE-2026-49105
CVE-2026-49104 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
CVE-2026-49104
CVE-2026-49085 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
CVE-2026-49085
