Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-49106 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact
CVE-2026-49106
CVE-2026-49105 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
CVE-2026-49105
CVE-2026-49104 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
CVE-2026-49104
CVE-2026-49085 - Contact Form 7 Plugin
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
CVE-2026-49085
CVE-2026-49112 - WordPress component
Unauthenticated Path Traversal in Shared Files
CVE-2026-49112
CVE-2026-49110 - WordPress component
Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce
CVE-2026-49110
CVE-2026-49083 - WordPress component
Contributor Privilege Escalation in LatePoint
CVE-2026-49083
CVE-2026-49082 - WordPress component
Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
CVE-2026-49082
CVE-2026-49067 - WordPress component
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect
CVE-2026-49067
CVE-2026-49065 - WordPress component
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce
CVE-2026-49065
CVE-2026-49078 - WordPress component
Unauthenticated Other Vulnerability Type in WP Travel Engine
CVE-2026-49078
CVE-2026-49070 - WordPress component
Unauthenticated Broken Access Control in Knit Pay
CVE-2026-49070
CVE-2026-49068 - WordPress component
Subscriber Sensitive Data Exposure in Coupon Affiliates
CVE-2026-49068
CVE-2026-49066 - WordPress component
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway
CVE-2026-49066
CVE-2026-49061 - WordPress component
Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce
CVE-2026-49061
CVE-2026-49063 - WordPress component
Unauthenticated Privilege Escalation in Listdom
CVE-2026-49063
CVE-2026-48889 - WordPress component
Subscriber Privilege Escalation in Amelia
CVE-2026-48889
CVE-2026-48964 - WordPress component
Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System
CVE-2026-48964
CVE-2026-48970 - WordPress component
Unauthenticated Broken Authentication in Really Simple SSL
CVE-2026-48970
CVE-2026-49056 - WordPress component
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels
CVE-2026-49056
