Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3061-3080 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-25001 - Post Snippets Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through

PLUGIN Post Snippets

CVE-2026-25001

HIGH CVSS 8.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25002 - LearnPress – Sepay Payment Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress – Sepay Payment: from n/a through

PLUGIN LearnPress – Sepay Payment

CVE-2026-25002

HIGH CVSS 7.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25013 - Phox Hosting Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a through

PLUGIN Phox Hosting

CVE-2026-25013

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-25009 - Education Zone Plugin

Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Zone: from n/a through

PLUGIN Education Zone

CVE-2026-25009

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24981 - Visionary Core Plugin

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through

PLUGIN Visionary Core

CVE-2026-24981

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24978 - Jobica Core Plugin

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through

PLUGIN Jobica Core

CVE-2026-24978

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24977 - Organici Library Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Organici Library: from n/a through

PLUGIN Organici Library

CVE-2026-24977

HIGH CVSS 8.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24983 - UpSolution Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from n/a through

PLUGIN UpSolution Core

CVE-2026-24983

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24980 - Visionary Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue affects Visionary Core: from n/a through

PLUGIN Visionary Core

CVE-2026-24980

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24979 - Jobica Core Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobica Core: from n/a through

PLUGIN Jobica Core

CVE-2026-24979

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24987 - WP System Log Plugin

Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a through

PLUGIN WP System Log

CVE-2026-24987

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24971 - Search & Go Plugin

Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through

PLUGIN Search & Go

CVE-2026-24971

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24976 - Organici Library Plugin

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through

PLUGIN Organici Library

CVE-2026-24976

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24974 - CitiLights Plugin

Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through

PLUGIN CitiLights

CVE-2026-24974

HIGH CVSS 8.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24975 - Organici Library Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici Library: from n/a through

PLUGIN Organici Library

CVE-2026-24975

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24973 - CitiLights Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme CitiLights noo-citilights allows Reflected XSS.This issue affects CitiLights: from n/a through

PLUGIN CitiLights

CVE-2026-24973

HIGH CVSS 7.1 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24972 - Elated Listing Plugin

Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a through

PLUGIN Elated Listing

CVE-2026-24972

MEDIUM CVSS 6.5 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24968 - Xagio SEO Plugin

Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through

PLUGIN Xagio SEO

CVE-2026-24968

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24378 - EventPrime Plugin

Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through

PLUGIN EventPrime

CVE-2026-24378

CRITICAL CVSS 9.8 2026-03-25
Threat Entry Updated 2026-06-17

CVE-2026-24970 - Energox Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through

PLUGIN Energox

CVE-2026-24970

HIGH CVSS 7.7 2026-03-25
Scroll to top