Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 2941-2960 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-32493 - JobSearch Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through

PLUGIN JobSearch

CVE-2026-32493

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32491 - WP Review Slider Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Review Slider wp-facebook-reviews allows Stored XSS.This issue affects WP Review Slider: from n/a through

PLUGIN WP Review Slider

CVE-2026-32491

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32490 - WP TripAdvisor Review Slider Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripAdvisor Review Slider wp-tripadvisor-review-slider allows Stored XSS.This issue affects WP TripAdvisor Review Slider: from n/a through

PLUGIN WP TripAdvisor Review Slider

CVE-2026-32490

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32492 - My Tickets Plugin

Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through

PLUGIN My Tickets

CVE-2026-32492

MEDIUM CVSS 5.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32482 - Ona Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: from n/a through < 1.24.

PLUGIN Ona

CVE-2026-32482

CRITICAL CVSS 9.9 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32484 - weForms Plugin

Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects weForms: from n/a through

PLUGIN weForms

CVE-2026-32484

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32488 - User Registration Plugin

Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n/a through

PLUGIN User Registration

CVE-2026-32488

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32441 - Comments Import & Export Plugin

Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comments Import & Export: from n/a through

PLUGIN Comments Import & Export

CVE-2026-32441

HIGH CVSS 7.7 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32485 - WP User Frontend Plugin

Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Frontend: from n/a through

PLUGIN WP User Frontend

CVE-2026-32485

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32489 - B Blocks Plugin

Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects B Blocks: from n/a through < 2.0.30.

PLUGIN B Blocks

CVE-2026-32489

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-32483 - Contact Form Email Plugin

Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through

PLUGIN Contact Form Email

CVE-2026-32483

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-31920 - Product Rearrange for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Blind SQL Injection.This issue affects Product Rearrange for WooCommerce: from n/a through

PLUGIN Product Rearrange for WooCommerce

CVE-2026-31920

CRITICAL CVSS 9.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-31913 - Scape Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16.

PLUGIN Scape

CVE-2026-31913

HIGH CVSS 8.6 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-31921 - Product Rearrange for WooCommerce Plugin

Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Rearrange for WooCommerce: from n/a through

PLUGIN Product Rearrange for WooCommerce

CVE-2026-31921

HIGH CVSS 8.2 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-31914 - WP Courses LMS Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Courses LMS wp-courses allows DOM-Based XSS.This issue affects WP Courses LMS: from n/a through

PLUGIN WP Courses LMS

CVE-2026-31914

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-27095 - Bus Ticket Booking with Seat Reservation Plugin

Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through

PLUGIN Bus Ticket Booking with Seat Reservation

CVE-2026-27095

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-27084 - Buisson Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through

PLUGIN Buisson

CVE-2026-27084

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-27088 - Darna Framework Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Darna Framework darna-framework allows Reflected XSS.This issue affects Darna Framework: from n/a through

PLUGIN Darna Framework

CVE-2026-27088

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-27087 - Wolverine Framework Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Wolverine Framework wolverine-framework allows Reflected XSS.This issue affects Wolverine Framework: from n/a through

PLUGIN Wolverine Framework

CVE-2026-27087

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-27083 - Work & Travel Company Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through

PLUGIN Work & Travel Company

CVE-2026-27083

CRITICAL CVSS 9.8 2026-03-25
Scroll to top