Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3701-3720 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-27376 - Claue - Clean, Minimal Elementor WooCommerce Theme

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Claue - Clean, Minimal Elementor WooCommerce Theme claue allows Reflected XSS.This issue affects Claue - Clean, Minimal Elementor WooCommerce Theme: from n/a through

THEME Claue - Clean, Minimal Elementor WooCommerce Theme

CVE-2026-27376

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27375 - Gecko Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Gecko gecko allows Reflected XSS.This issue affects Gecko: from n/a through

PLUGIN Gecko

CVE-2026-27375

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27373 - Tablesome Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome tablesome allows Blind SQL Injection.This issue affects Tablesome: from n/a through

PLUGIN Tablesome

CVE-2026-27373

HIGH CVSS 8.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27369 - Celeste Plugin

Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through

PLUGIN Celeste

CVE-2026-27369

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27374 - WooCommerce Order Details Plugin

Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Order Details: from n/a through

PLUGIN WooCommerce Order Details

CVE-2026-27374

HIGH CVSS 7.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27370 - Chaty Plugin

Insertion of Sensitive Information Into Sent Data vulnerability in Premio Chaty chaty allows Retrieve Embedded Sensitive Data.This issue affects Chaty: from n/a through

PLUGIN Chaty

CVE-2026-27370

HIGH CVSS 7.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27367 - Musico Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through < 3.4.5.

PLUGIN Musico

CVE-2026-27367

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27363 - WP Bakery Autoresponder Addon Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Stored XSS.This issue affects WP Bakery Autoresponder Addon: from n/a through

PLUGIN WP Bakery Autoresponder Addon

CVE-2026-27363

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27362 - WP Bakery Autoresponder Addon Plugin

Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bakery Autoresponder Addon: from n/a through

PLUGIN WP Bakery Autoresponder Addon

CVE-2026-27362

MEDIUM CVSS 6.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27361 - Responsive Posts Carousel Pro Plugin

Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Posts Carousel Pro: from n/a through

PLUGIN Responsive Posts Carousel Pro

CVE-2026-27361

HIGH CVSS 7.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27359 - Awa Plugins

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Awa Plugins awa-plugins allows Reflected XSS.This issue affects Awa Plugins: from n/a through

PLUGIN Awa Plugins

CVE-2026-27359

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27358 - Architecturer Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through < 3.9.5.

PLUGIN Architecturer

CVE-2026-27358

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27353 - Grand News Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand News grandnews allows Reflected XSS.This issue affects Grand News: from n/a through

PLUGIN Grand News

CVE-2026-27353

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27352 - Starto Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through < 2.2.5.

PLUGIN Starto

CVE-2026-27352

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27348 - Photography Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows DOM-Based XSS.This issue affects Photography: from n/a through < 7.7.6.

PLUGIN Photography

CVE-2026-27348

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27354 - WooCommerce Coming Soon Product with Countdown Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows Stored XSS.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through

PLUGIN WooCommerce Coming Soon Product with Countdown

CVE-2026-27354

MEDIUM CVSS 6.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27344 - inseri core Plugin

Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through

PLUGIN inseri core

CVE-2026-27344

MEDIUM CVSS 5.9 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27338 - Car Zone Plugin

Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through

PLUGIN Car Zone

CVE-2026-27338

HIGH CVSS 8.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27342 - TopFit - Fitness and Gym WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopFit - Fitness and Gym WordPress Theme topfit allows PHP Local File Inclusion.This issue affects TopFit - Fitness and Gym WordPress Theme: from n/a through

THEME TopFit - Fitness and Gym WordPress Theme

CVE-2026-27342

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-27341 - TopScorer - Sports WordPress Theme

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through

THEME TopScorer - Sports WordPress Theme

CVE-2026-27341

HIGH CVSS 8.1 2026-03-05
Scroll to top