Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
CVE-2026-40772 - WordPress component
Unauthenticated Arbitrary File Upload in GeekyBot
CVE-2026-40772
CVE-2026-40771 - WordPress component
Unauthenticated SQL Injection in Contest Gallery
CVE-2026-40771
CVE-2026-40769 - WordPress component
Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field
CVE-2026-40769
CVE-2026-40766 - WordPress component
Subscriber SQL Injection in MasterStudy LMS
CVE-2026-40766
CVE-2026-40767 - WordPress component
Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
CVE-2026-40767
CVE-2026-40762 - WordPress component
Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
CVE-2026-40762
CVE-2026-40770 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates
CVE-2026-40770
CVE-2026-40773 - WordPress Core
Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress
CVE-2026-40773
CVE-2026-40743 - WordPress component
Unauthenticated Broken Access Control in Tutor LMS
CVE-2026-40743
CVE-2026-39591 - WordPress component
Subscriber Arbitrary File Upload in WP-BusinessDirectory
CVE-2026-39591
CVE-2026-40727 - WordPress component
Sales Representative Arbitrary File Deletion in Groundhogg
CVE-2026-40727
CVE-2026-40741 - WordPress component
Unauthenticated Broken Access Control in Redsys for WooCommerce Light
CVE-2026-40741
CVE-2026-40732 - WordPress component
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram
CVE-2026-40732
CVE-2026-39594 - WPForms Plugin
Subscriber Broken Access Control in Ultra Addons for WPForms
CVE-2026-39594
CVE-2026-39583 - WordPress component
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery
CVE-2026-39583
CVE-2026-39579 - WordPress component
Contributor Privilege Escalation in B Blocks
CVE-2026-39579
CVE-2026-39532 - WordPress component
Contributor PHP Object Injection in Events Calendar for GeoDirectory
CVE-2026-39532
CVE-2026-39587 - WordPress component
Unauthenticated Privilege Escalation in WP BASE Booking
CVE-2026-39587
CVE-2026-39534 - WordPress component
Unauthenticated Broken Access Control in WP Directory Kit
CVE-2026-39534
CVE-2026-39533 - WordPress component
Unauthenticated Broken Access Control in AWP Classifieds
CVE-2026-39533
