Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-39478 - WordPress component
Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall
CVE-2026-39478
CVE-2026-39474 - WordPress component
Contributor PHP Object Injection in Post Duplicator
CVE-2026-39474
CVE-2026-39480 - WordPress component
Unauthenticated Sensitive Data Exposure in Backup Migration
CVE-2026-39480
CVE-2026-39481 - WordPress component
Author PHP Object Injection in Modula Image Gallery
CVE-2026-39481
CVE-2026-39491 - WordPress component
Subscriber Cross Site Scripting (XSS) in JupiterX Core
CVE-2026-39491
CVE-2026-39489 - WordPress component
Author Arbitrary File Download in Download Monitor
CVE-2026-39489
CVE-2026-39465 - WordPress component
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider
CVE-2026-39465
CVE-2026-39472 - WordPress component
Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
CVE-2026-39472
CVE-2026-39471 - WordPress component
Author PHP Object Injection in ShortPixel Image Optimizer
CVE-2026-39471
CVE-2026-39470 - WordPress component
Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
CVE-2026-39470
CVE-2026-39463 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker
CVE-2026-39463
CVE-2026-39450 - WordPress component
Subscriber Broken Authentication in FunnelKit Automations
CVE-2026-39450
CVE-2026-39449 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API
CVE-2026-39449
CVE-2026-39468 - WordPress Core
Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework
CVE-2026-39468
CVE-2026-39451 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider
CVE-2026-39451
CVE-2026-34901 - WordPress component
Unauthenticated Privilege Escalation in iControlWP
CVE-2026-34901
CVE-2026-39441 - WordPress component
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free
CVE-2026-39441
CVE-2026-39434 - WordPress component
Shop manager PHP Object Injection in CTX Feed
CVE-2026-39434
CVE-2026-39447 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments
CVE-2026-39447
CVE-2026-39435 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in CformsII
CVE-2026-39435
