Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 2981-3000 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-25464 - Jannah Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through

PLUGIN Jannah

CVE-2026-25464

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25458 - Moments Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Moments moments allows PHP Local File Inclusion.This issue affects Moments: from n/a through

PLUGIN Moments

CVE-2026-25458

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25461 - Listeo Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo Core listeo-core allows Reflected XSS.This issue affects Listeo Core: from n/a through

PLUGIN Listeo Core

CVE-2026-25461

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25469 - ViaBill – WooCommerce Plugin

Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ViaBill – WooCommerce: from n/a through

PLUGIN ViaBill – WooCommerce

CVE-2026-25469

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25465 - CP Multi View Event Calendar Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Stored XSS.This issue affects CP Multi View Event Calendar : from n/a through

PLUGIN CP Multi View Event Calendar

CVE-2026-25465

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25462 - Avalex Plugin

Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects avalex: from n/a through

PLUGIN Avalex

CVE-2026-25462

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25460 - Ave Core Plugin

Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ave Core: from n/a through

PLUGIN Ave Core

CVE-2026-25460

MEDIUM CVSS 6.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25457 - Mixtape Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Mixtape mixtape allows PHP Local File Inclusion.This issue affects Mixtape: from n/a through

PLUGIN Mixtape

CVE-2026-25457

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25456 - Automated FedEx live/manual rates with shipping labels Plugin

Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Automated FedEx live/manual rates with shipping labels: from n/a through

PLUGIN Automated FedEx live/manual rates with shipping labels

CVE-2026-25456

HIGH CVSS 7.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25452 - Remoji Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDO Remoji remoji allows Stored XSS.This issue affects Remoji: from n/a through

PLUGIN Remoji

CVE-2026-25452

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25455 - Product Slider for WooCommerce Plugin

Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Slider for WooCommerce: from n/a through

PLUGIN Product Slider for WooCommerce

CVE-2026-25455

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25454 - The League Plugin

Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The League: from n/a through

PLUGIN The League

CVE-2026-25454

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25413 - WPBookit Pro Plugin

Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through

PLUGIN WPBookit Pro

CVE-2026-25413

CRITICAL CVSS 9.9 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25429 - Nexa Blocks Plugin

Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a through

PLUGIN Nexa Blocks

CVE-2026-25429

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25447 - Widget Wrangler Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.This issue affects Widget Wrangler: from n/a through

PLUGIN Widget Wrangler

CVE-2026-25447

CRITICAL CVSS 9.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25414 - WPBookit Pro Plugin

Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through

PLUGIN WPBookit Pro

CVE-2026-25414

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25435 - Booking calendar, Appointment Booking System Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking System: from n/a through

PLUGIN Booking calendar, Appointment Booking System

CVE-2026-25435

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25437 - GZSEO Plugin

Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GZSEO: from n/a through

PLUGIN GZSEO

CVE-2026-25437

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25430 - Contact Form 7 Plugin

Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms cf7-mailchimp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through

PLUGIN Contact Form 7

CVE-2026-25430

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25417 - ProfileGrid Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through

PLUGIN ProfileGrid

CVE-2026-25417

MEDIUM CVSS 6.5 2026-03-25
Scroll to top