sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total13,208
Critical0
High0
Medium13,208
Reset
Showing 21-40 of 13208 records
Threat Entry Updated 2026-09-03

Learnpress - Security Vulnerability (CVE-2026-82024)

LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persistent malicious payloads by submitting unsanitized input into quiz question answer title fields. Attackers can store arbitrary JavaScript through the answer title parameter, which is rendered through an unescaped HTML sink to execute in the browsers of any user who views the affected quiz question, including students, other instructors, and administrators.

PLUGIN Learnpress

CVE-2026-82024

MEDIUM CVSS 5.1 2026-09-03
Threat Entry Updated 2026-09-03

SureForms - Security Vulnerability (CVE-2026-85308)

Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5.

PLUGIN SureForms

CVE-2026-85308

MEDIUM CVSS 5.3 2026-09-03
Threat Entry Updated 2026-09-04

MountDev AI MCP Connector for WordPress - Security Vulnerability (CVE-2026-85306)

Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5.

PLUGIN MountDev AI MCP Connector for WordPress

CVE-2026-85306

MEDIUM CVSS 6.5 2026-09-03
Threat Entry Updated 2026-09-03

Elementor - Security Vulnerability (CVE-2026-85302)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2.

PLUGIN Elementor

CVE-2026-85302

MEDIUM CVSS 6.5 2026-09-03
Threat Entry Updated 2026-09-03

Elementor - Security Vulnerability (CVE-2026-85304)

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17.

PLUGIN Elementor

CVE-2026-85304

MEDIUM CVSS 5.3 2026-09-03