Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 321-340 of 4286 records
Threat Entry Updated 2026-06-26

CVE-2026-10835 - Before 3 Plugin

The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal permissions, such as subscribers, to perform SQL injection attacks.

PLUGIN Before 3

CVE-2026-10835

HIGH CVSS 7.7 2026-06-26
Threat Entry Updated 2026-06-26

CVE-2026-10823 - Ymc Filter Plugin

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-supplied query parameter, allowing unauthenticated attackers to retrieve the titles and content of private, draft, and other non-public posts.

PLUGIN Ymc Filter

CVE-2026-10823

HIGH CVSS 7.5 2026-06-26
Threat Entry Updated 2026-06-25

CVE-2026-54848 - APIExperts Square for WooCommerce Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.

PLUGIN APIExperts Square for WooCommerce

CVE-2026-54848

HIGH CVSS 8.3 2026-06-25
Scroll to top