Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3401-3420 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-32373 - SMS Alert Order Notifications Plugin

Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through

PLUGIN SMS Alert Order Notifications

CVE-2026-32373

MEDIUM CVSS 5.4 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32374 - The Minimal Plugin

Missing Authorization vulnerability in raratheme The Minimal the-minimal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Minimal: from n/a through

PLUGIN The Minimal

CVE-2026-32374

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32372 - Elementor Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through

PLUGIN Elementor

CVE-2026-32372

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32371 - Elegant Pink Plugin

Missing Authorization vulnerability in raratheme Elegant Pink elegant-pink allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elegant Pink: from n/a through

PLUGIN Elegant Pink

CVE-2026-32371

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32370 - Influencer Plugin

Missing Authorization vulnerability in raratheme Influencer influencer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Influencer: from n/a through

PLUGIN Influencer

CVE-2026-32370

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32367 - Modal Dialog Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through

PLUGIN Modal Dialog

CVE-2026-32367

CRITICAL CVSS 9.1 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32366 - Collapsing Categories Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categories allows Blind SQL Injection.This issue affects Collapsing Categories: from n/a through

PLUGIN Collapsing Categories

CVE-2026-32366

HIGH CVSS 8.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32365 - Collapsing Archives Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through

PLUGIN Collapsing Archives

CVE-2026-32365

HIGH CVSS 8.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32364 - Turbo Manager Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8.

PLUGIN Turbo Manager

CVE-2026-32364

HIGH CVSS 7.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32363 - WPLifeCycle Plugin

Missing Authorization vulnerability in Funlus Oy WPLifeCycle free-php-version-info allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLifeCycle: from n/a through

PLUGIN WPLifeCycle

CVE-2026-32363

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32362 - WP Sessions Time Monitoring Full Automatic Plugin

Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through

PLUGIN WP Sessions Time Monitoring Full Automatic

CVE-2026-32362

MEDIUM CVSS 5.3 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32358 - Booking Calendar Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar: from n/a through

PLUGIN Booking Calendar

CVE-2026-32358

HIGH CVSS 7.6 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32361 - Editorial Calendar Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows DOM-Based XSS.This issue affects Editorial Calendar: from n/a through

PLUGIN Editorial Calendar

CVE-2026-32361

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32359 - Icon List Block Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through

PLUGIN Icon List Block

CVE-2026-32359

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32357 - Simple Blog Card Plugin

Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Side Request Forgery.This issue affects Simple Blog Card: from n/a through

PLUGIN Simple Blog Card

CVE-2026-32357

MEDIUM CVSS 6.4 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32360 - Rich Showcase for Google Reviews Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue affects Rich Showcase for Google Reviews: from n/a through

PLUGIN Rich Showcase for Google Reviews

CVE-2026-32360

MEDIUM CVSS 5.9 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32355 - JetEngine Plugin

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

PLUGIN JetEngine

CVE-2026-32355

HIGH CVSS 8.8 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32356 - Robo Gallery Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows DOM-Based XSS.This issue affects Robo Gallery: from n/a through

PLUGIN Robo Gallery

CVE-2026-32356

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32352 - Elementor Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows DOM-Based XSS.This issue affects Elementor Website Builder: from n/a through

PLUGIN Elementor

CVE-2026-32352

MEDIUM CVSS 6.5 2026-03-13
Threat Entry Updated 2026-06-17

CVE-2026-32353 - MailerPress Plugin

Server-Side Request Forgery (SSRF) vulnerability in MailerPress Team MailerPress mailerpress allows Server Side Request Forgery.This issue affects MailerPress: from n/a through

PLUGIN MailerPress

CVE-2026-32353

MEDIUM CVSS 6.4 2026-03-13
Scroll to top