Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3341-3360 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-32433 - CP Contact Form with Paypal Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through

PLUGIN CP Contact Form with Paypal

CVE-2026-32433

HIGH CVSS 8.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32431 - Astra Bulk Edit Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edit allows DOM-Based XSS.This issue affects Astra Bulk Edit: from n/a through

PLUGIN Astra Bulk Edit

CVE-2026-32431

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32430 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations PowerPack Addons for Elementor powerpack-lite-for-elementor allows Stored XSS.This issue affects PowerPack Addons for Elementor: from n/a through

PLUGIN Elementor

CVE-2026-32430

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32432 - WP Time Slots Booking Form Plugin

Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through

PLUGIN WP Time Slots Booking Form

CVE-2026-32432

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32429 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Stored XSS.This issue affects Magical Addons For Elementor: from n/a through

PLUGIN Elementor

CVE-2026-32429

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32428 - Popup Like box Plugin

Missing Authorization vulnerability in Ays Pro Popup Like box ays-facebook-popup-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Like box: from n/a through

PLUGIN Popup Like box

CVE-2026-32428

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32427 - VW Education Lite Plugin

Missing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Education Lite: from n/a through

PLUGIN VW Education Lite

CVE-2026-32427

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32422 - WP EasyCart Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in levelfourdevelopment WP EasyCart wp-easycart allows Blind SQL Injection.This issue affects WP EasyCart: from n/a through

PLUGIN WP EasyCart

CVE-2026-32422

HIGH CVSS 8.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32426 - Medilazar Core Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Medilazar Core medilazar-core allows PHP Local File Inclusion.This issue affects Medilazar Core: from n/a through < 1.4.7.

PLUGIN Medilazar Core

CVE-2026-32426

HIGH CVSS 7.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32424 - Sprout Clients Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through

PLUGIN Sprout Clients

CVE-2026-32424

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32423 - Admin and Site Enhancements (ASE Plugin

Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through

PLUGIN Admin and Site Enhancements (ASE

CVE-2026-32423

MEDIUM CVSS 5.4 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32425 - Payment Gateway Pix For GiveWP Plugin

Missing Authorization vulnerability in linknacional Payment Gateway Pix For GiveWP payment-gateway-pix-for-givewp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payment Gateway Pix For GiveWP: from n/a through

PLUGIN Payment Gateway Pix For GiveWP

CVE-2026-32425

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32418 - Meow Gallery Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jordy Meow Meow Gallery meow-gallery allows Blind SQL Injection.This issue affects Meow Gallery: from n/a through

PLUGIN Meow Gallery

CVE-2026-32418

HIGH CVSS 7.6 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32419 - List category posts Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fernando Briano List category posts list-category-posts allows DOM-Based XSS.This issue affects List category posts: from n/a through

PLUGIN List category posts

CVE-2026-32419

MEDIUM CVSS 5.9 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32420 - GamiPress Plugin

Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: from n/a through

PLUGIN GamiPress

CVE-2026-32420

MEDIUM CVSS 5.4 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32417 - Pochipp Plugin

Missing Authorization vulnerability in wppochipp Pochipp pochipp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pochipp: from n/a through < 1.18.9.

PLUGIN Pochipp

CVE-2026-32417

MEDIUM CVSS 5.4 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32421 - Post Timeline Plugin

Missing Authorization vulnerability in Agile Logix Post Timeline post-timeline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Timeline: from n/a through

PLUGIN Post Timeline

CVE-2026-32421

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32414 - Advanced Woo Labels Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in ILLID Advanced Woo Labels advanced-woo-labels allows Remote Code Inclusion.This issue affects Advanced Woo Labels: from n/a through

PLUGIN Advanced Woo Labels

CVE-2026-32414

HIGH CVSS 7.2 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32411 - Embed Calendly Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed Calendly embed-calendly-scheduling allows Stored XSS.This issue affects Embed Calendly: from n/a through

PLUGIN Embed Calendly

CVE-2026-32411

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32416 - PDF Poster Plugin

Missing Authorization vulnerability in bPlugins PDF Poster pdf-poster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF Poster: from n/a through

PLUGIN PDF Poster

CVE-2026-32416

MEDIUM CVSS 5.4 2026-03-13
Scroll to top