Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,248
Critical1,270
High4,357
Medium12,382
Reset
Showing 3741-3760 of 18248 records
Threat Entry Updated 2026-06-17

CVE-2026-22475 - Estate Plugin

Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through

PLUGIN Estate

CVE-2026-22475

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22474 - Equestrian Centre Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through

PLUGIN Equestrian Centre

CVE-2026-22474

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22478 - FindAll Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes FindAll findall allows PHP Local File Inclusion.This issue affects FindAll: from n/a through

PLUGIN FindAll

CVE-2026-22478

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22477 - Felizia Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Felizia felizia allows PHP Local File Inclusion.This issue affects Felizia: from n/a through

PLUGIN Felizia

CVE-2026-22477

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22476 - Etchy Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Etchy etchy allows PHP Local File Inclusion.This issue affects Etchy: from n/a through

PLUGIN Etchy

CVE-2026-22476

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22479 - Easy Post Submission Plugin

Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Post Submission: from n/a through

PLUGIN Easy Post Submission

CVE-2026-22479

HIGH CVSS 7.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22473 - Dental Clinic Plugin

Deserialization of Untrusted Data vulnerability in designthemes Dental Clinic dental allows Object Injection.This issue affects Dental Clinic: from n/a through

PLUGIN Dental Clinic

CVE-2026-22473

HIGH CVSS 8.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22471 - Secudeal Payments for Ecommerce Plugin

Deserialization of Untrusted Data vulnerability in maximsecudeal Secudeal Payments for Ecommerce secudeal-payments-for-ecommerce allows Object Injection.This issue affects Secudeal Payments for Ecommerce: from n/a through

PLUGIN Secudeal Payments for Ecommerce

CVE-2026-22471

HIGH CVSS 8.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22460 - FormGent Plugin

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpWax FormGent formgent allows Path Traversal.This issue affects FormGent: from n/a through

PLUGIN FormGent

CVE-2026-22460

HIGH CVSS 8.6 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22457 - Wanderland Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This issue affects Wanderland: from n/a through

PLUGIN Wanderland

CVE-2026-22457

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22467 - DeepDigital Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mwtemplates DeepDigital deepdigital allows Reflected XSS.This issue affects DeepDigital: from n/a through

PLUGIN DeepDigital

CVE-2026-22467

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22465 - BuddyApp Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen BuddyApp buddyapp allows Reflected XSS.This issue affects BuddyApp: from n/a through

PLUGIN BuddyApp

CVE-2026-22465

HIGH CVSS 7.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22459 - WordPress CTA Plugin

Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress CTA: from n/a through

PLUGIN WordPress CTA

CVE-2026-22459

MEDIUM CVSS 6.5 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22454 - Solaris Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects Solaris: from n/a through

PLUGIN Solaris

CVE-2026-22454

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22453 - Pets Club Plugin

Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through

PLUGIN Pets Club

CVE-2026-22453

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22451 - Handyman Plugin

Deserialization of Untrusted Data vulnerability in AncoraThemes Handyman handyman-services allows Object Injection.This issue affects Handyman: from n/a through

PLUGIN Handyman

CVE-2026-22451

CRITICAL CVSS 9.8 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22456 - Askka Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Askka askka allows PHP Local File Inclusion.This issue affects Askka: from n/a through

PLUGIN Askka

CVE-2026-22456

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22452 - Hoverex Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hoverex hoverex allows PHP Local File Inclusion.This issue affects Hoverex: from n/a through

PLUGIN Hoverex

CVE-2026-22452

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22449 - Don Peppe Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through

PLUGIN Don Peppe

CVE-2026-22449

HIGH CVSS 8.1 2026-03-05
Threat Entry Updated 2026-06-17

CVE-2026-22446 - Prowess Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Prowess prowess allows PHP Local File Inclusion.This issue affects Prowess: from n/a through

PLUGIN Prowess

CVE-2026-22446

HIGH CVSS 8.1 2026-03-05
Scroll to top