Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-56014 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Master Slider
CVE-2026-56014
CVE-2026-56006 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in H5P
CVE-2026-56006
CVE-2026-56050 - PPOM for WooCommerce Plugin
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a through 33.0.18.
CVE-2026-56050
CVE-2026-56013 - WordPress component
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce
CVE-2026-56013
CVE-2026-56023 - WordPress component
Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce
CVE-2026-56023
CVE-2026-54849 - WordPress component
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce
CVE-2026-54849
CVE-2026-54848 - APIExperts Square for WooCommerce Plugin
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.
CVE-2026-54848
CVE-2026-56005 - WordPress component
Subscriber Cross Site Scripting (XSS) in WP Activity Log
CVE-2026-56005
CVE-2026-54843 - WordPress component
Unauthenticated SQL Injection in MDTF
CVE-2026-54843
CVE-2026-54845 - WordPress component
Unauthenticated Local File Inclusion in MDTF
CVE-2026-54845
CVE-2026-54842 - Royal MCP Plugin
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.
CVE-2026-54842
CVE-2026-54844 - WordPress component
Unauthenticated Broken Access Control in CheckView Automated Testing
CVE-2026-54844
CVE-2026-54841 - WordPress component
Unauthenticated Sensitive Data Exposure in Vitepos
CVE-2026-54841
CVE-2026-54836 - YMC Filter Plugin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5.
CVE-2026-54836
CVE-2026-54838 - WordPress component
Subscriber SQL Injection in WC Vendors Marketplace
CVE-2026-54838
CVE-2026-54830 - WordPress component
Unauthenticated Broken Access Control in Five Star Restaurant Reservations
CVE-2026-54830
CVE-2026-54829 - WP Photo Album Plus Plugin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.
CVE-2026-54829
CVE-2026-54823 - WordPress component
Contributor Remote Code Execution (RCE) in Widget Options
CVE-2026-54823
CVE-2026-54822 - WordPress component
Subscriber SQL Injection in SALESmanago & Leadoo
CVE-2026-54822
CVE-2026-54828 - WordPress component
Unauthenticated Broken Access Control in Motors
CVE-2026-54828
