Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 181-200 of 18002 records
Threat Entry Updated 2026-07-13

CVE-2026-57778 - Booking calendar, Appointment Booking System Plugin

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through

PLUGIN Booking calendar, Appointment Booking System

CVE-2026-57778

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57776 - VW Wedding Plugin

Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through

PLUGIN VW Wedding

CVE-2026-57776

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57774 - VW Food Corner Plugin

Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through

PLUGIN VW Food Corner

CVE-2026-57774

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57744 - RT-Theme 18 | Extensions

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through

THEME RT-Theme 18 | Extensions

CVE-2026-57744

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57738 - 777 Plugin

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through

PLUGIN 777

CVE-2026-57738

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57739 - AcyMailing SMTP Newsletter Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through

PLUGIN AcyMailing SMTP Newsletter

CVE-2026-57739

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57768 - Houzez Login Register Plugin

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through

PLUGIN Houzez Login Register

CVE-2026-57768

HIGH CVSS 8.2 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57743 - RT-Theme 18 | Extensions

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through

THEME RT-Theme 18 | Extensions

CVE-2026-57743

HIGH CVSS 8.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57745 - RT-Theme 18 | Extensions

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through

THEME RT-Theme 18 | Extensions

CVE-2026-57745

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57741 - AcyMailing SMTP Newsletter Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through

PLUGIN AcyMailing SMTP Newsletter

CVE-2026-57741

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57740 - AcyMailing SMTP Newsletter Plugin

Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through

PLUGIN AcyMailing SMTP Newsletter

CVE-2026-57740

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57724 - Kirki Plugin

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through

PLUGIN Kirki

CVE-2026-57724

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57726 - Kirki Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through

PLUGIN Kirki

CVE-2026-57726

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57729 - Flatsome Plugin

Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a through

PLUGIN Flatsome

CVE-2026-57729

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57727 - Kirki Plugin

Missing Authorization vulnerability in Themeum Kirki kirki allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kirki: from n/a through

PLUGIN Kirki

CVE-2026-57727

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57734 - tagDiv Composer Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Reflected XSS.This issue affects tagDiv Composer: from n/a through

PLUGIN tagDiv Composer

CVE-2026-57734

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57733 - tagDiv Cloud Library Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Cloud Library td-cloud-library allows DOM-Based XSS.This issue affects tagDiv Cloud Library: from n/a through

PLUGIN tagDiv Cloud Library

CVE-2026-57733

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57732 - tagDiv Opt-In Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows DOM-Based XSS.This issue affects tagDiv Opt-In Builder: from n/a through

PLUGIN tagDiv Opt-In Builder

CVE-2026-57732

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57728 - Flatsome Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: from n/a through

PLUGIN Flatsome

CVE-2026-57728

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57725 - Kirki Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Kirki kirki allows Stored XSS.This issue affects Kirki: from n/a through

PLUGIN Kirki

CVE-2026-57725

HIGH CVSS 7.1 2026-07-13
Scroll to top