Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4,286
Critical0
High4,286
Medium0
Reset
Showing 101-120 of 4286 records
Threat Entry Updated 2026-07-13

CVE-2026-57389 - Groundhogg Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through

PLUGIN Groundhogg

CVE-2026-57389

HIGH CVSS 8.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57394 - Newsletters Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through

PLUGIN Newsletters

CVE-2026-57394

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57388 - Hydra Booking Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through

PLUGIN Hydra Booking

CVE-2026-57388

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57386 - aBlocks Plugin

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

PLUGIN aBlocks

CVE-2026-57386

HIGH CVSS 8.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57385 - Vitepos Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through

PLUGIN Vitepos

CVE-2026-57385

HIGH CVSS 8.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57387 - Picu Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through

PLUGIN Picu

CVE-2026-57387

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57383 - JobSearch Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through

PLUGIN JobSearch

CVE-2026-57383

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57382 - Simple File List Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through

PLUGIN Simple File List

CVE-2026-57382

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57381 - PropertyHive Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through

PLUGIN PropertyHive

CVE-2026-57381

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57380 - Extensions for Leaflet Map Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through

PLUGIN Extensions for Leaflet Map

CVE-2026-57380

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57379 - FormyChat Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through

PLUGIN FormyChat

CVE-2026-57379

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57371 - WPJAM Basic Plugin

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through

PLUGIN WPJAM Basic

CVE-2026-57371

HIGH CVSS 8.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57378 - Advanced Forms Plugin

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through

PLUGIN Advanced Forms

CVE-2026-57378

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57372 - WPJAM Basic Plugin

Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through

PLUGIN WPJAM Basic

CVE-2026-57372

HIGH CVSS 7.2 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57376 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through

PLUGIN Elementor

CVE-2026-57376

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57369 - Themify Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through

PLUGIN Themify Builder

CVE-2026-57369

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57368 - Jobmonster Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through

PLUGIN Jobmonster

CVE-2026-57368

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57363 - ChatBot Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through

PLUGIN ChatBot

CVE-2026-57363

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-12582 - Library Management System Plugin

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection and extract arbitrary data from the database, including user password hashes.

PLUGIN Library Management System

CVE-2026-12582

HIGH CVSS 8.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-11963 - Before 5 Plugin

The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier.

PLUGIN Before 5

CVE-2026-11963

HIGH CVSS 8.1 2026-07-13
Scroll to top