Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 201-220 of 18002 records
Threat Entry Updated 2026-07-13

CVE-2026-57719 - Aimogen Pro Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through

PLUGIN Aimogen Pro

CVE-2026-57719

CRITICAL CVSS 10.0 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57710 - WoowBot Pro Max Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through

PLUGIN WoowBot Pro Max

CVE-2026-57710

CRITICAL CVSS 9.9 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57714 - LatePoint Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through

PLUGIN LatePoint

CVE-2026-57714

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57713 - Events Manager Plugin

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through

PLUGIN Events Manager

CVE-2026-57713

HIGH CVSS 8.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57709 - Membership For WooCommerce Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through

PLUGIN Membership For WooCommerce

CVE-2026-57709

HIGH CVSS 8.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57718 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through

PLUGIN Elementor

CVE-2026-57718

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57715 - Fluent CRM Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fluent CRM: from n/a through

PLUGIN Fluent CRM

CVE-2026-57715

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57712 - WPZOOM Portfolio Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through

PLUGIN WPZOOM Portfolio

CVE-2026-57712

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57711 - SupportCandy Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through

PLUGIN SupportCandy

CVE-2026-57711

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57707 - Simple Business Directory Pro Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through

PLUGIN Simple Business Directory Pro

CVE-2026-57707

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57702 - Amelia Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through

PLUGIN Amelia

CVE-2026-57702

CRITICAL CVSS 9.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57705 - Event Tickets Plugin

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through

PLUGIN Event Tickets

CVE-2026-57705

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57697 - ProfileGrid Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through

PLUGIN ProfileGrid

CVE-2026-57697

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57708 - Contact Form Entries Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through

PLUGIN Contact Form Entries

CVE-2026-57708

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57706 - Dokan Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through

PLUGIN Dokan

CVE-2026-57706

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57695 - Document Gallery Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through

PLUGIN Document Gallery

CVE-2026-57695

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57698 - Abandoned Cart Recovery for WooCommerce Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through

PLUGIN Abandoned Cart Recovery for WooCommerce

CVE-2026-57698

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57668 - NEX-Forms Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through

PLUGIN NEX-Forms

CVE-2026-57668

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57423 - Contact Form 7 Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through

PLUGIN Contact Form 7

CVE-2026-57423

HIGH CVSS 7.1 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57422 - Bopo – WooCommerce Product Bundle Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through

PLUGIN Bopo – WooCommerce Product Bundle Builder

CVE-2026-57422

HIGH CVSS 7.1 2026-07-13
Scroll to top