Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 1041-1060 of 18002 records
Threat Entry Updated 2026-06-17

CVE-2026-8089 - Email Optins For Woocommerce Plugin

The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

PLUGIN Email Optins For Woocommerce

CVE-2026-8089

HIGH CVSS 7.1 2026-06-17
Threat Entry Updated 2026-06-17

CVE-2026-7850 - Wp Magnific Popup Plugin

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.

PLUGIN Wp Magnific Popup

CVE-2026-7850

MEDIUM CVSS 5.9 2026-06-17
Scroll to top