Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3041-3060 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-25339 - WPForms Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n/a through

PLUGIN WPForms

CVE-2026-25339

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25327 - Five Star Restaurant Reservations Plugin

Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through

PLUGIN Five Star Restaurant Reservations

CVE-2026-25327

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25035 - Contest Gallery Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Contest Gallery: from n/a through

PLUGIN Contest Gallery

CVE-2026-25035

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25317 - Print Invoice & Delivery Notes for WooCommerce Plugin

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through

PLUGIN Print Invoice & Delivery Notes for WooCommerce

CVE-2026-25317

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25309 - PublishPress Authors Plugin

Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through

PLUGIN PublishPress Authors

CVE-2026-25309

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25306 - XStore Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through

PLUGIN XStore Core

CVE-2026-25306

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25304 - Jaroti Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Jaroti jaroti allows Reflected XSS.This issue affects Jaroti: from n/a through < 1.4.8.

PLUGIN Jaroti

CVE-2026-25304

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25033 - Motta Addons Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uixthemes Motta Addons motta-addons allows Reflected XSS.This issue affects Motta Addons: from n/a through < 1.6.1.

PLUGIN Motta Addons

CVE-2026-25033

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25034 - KiviCare Plugin

Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through

PLUGIN KiviCare

CVE-2026-25034

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25032 - Ricky Plugin

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

PLUGIN Ricky

CVE-2026-25032

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25031 - Tasty Daily Plugin

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

PLUGIN Tasty Daily

CVE-2026-25031

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25030 - Goldish Plugin

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

PLUGIN Goldish

CVE-2026-25030

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25029 - KIDZ Plugin

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through

PLUGIN KIDZ

CVE-2026-25029

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25017 - NaturaLife Extensions Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows PHP Local File Inclusion.This issue affects NaturaLife Extensions: from n/a through

PLUGIN NaturaLife Extensions

CVE-2026-25017

HIGH CVSS 8.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25026 - Team Plugin

Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through

PLUGIN Team

CVE-2026-25026

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25025 - VikRestaurants Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through

PLUGIN VikRestaurants

CVE-2026-25025

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25018 - NaturaLife Extensions Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects NaturaLife Extensions: from n/a through

PLUGIN NaturaLife Extensions

CVE-2026-25018

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24989 - SUMO Affiliates Pro Plugin

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.

PLUGIN SUMO Affiliates Pro

CVE-2026-24989

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24993 - Advanced WooCommerce Product Sales Reporting Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statistics allows Blind SQL Injection.This issue affects Advanced WooCommerce Product Sales Reporting: from n/a through

PLUGIN Advanced WooCommerce Product Sales Reporting

CVE-2026-24993

CRITICAL CVSS 9.3 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25007 - Elementor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Blind SQL Injection.This issue affects ElementInvader Addons for Elementor: from n/a through

PLUGIN Elementor

CVE-2026-25007

HIGH CVSS 8.5 2026-03-25
Scroll to top