Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,002
Critical1,249
High4,286
Medium12,246
Reset
Showing 161-180 of 18002 records
Threat Entry Updated 2026-07-13

CVE-2026-57795 - Kitchor Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through

PLUGIN Kitchor

CVE-2026-57795

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57794 - Golo Framework Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through

PLUGIN Golo Framework

CVE-2026-57794

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57793 - Flow Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through

PLUGIN Flow

CVE-2026-57793

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57792 - Dør Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through

PLUGIN Dør

CVE-2026-57792

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57791 - Brook Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through

PLUGIN Brook

CVE-2026-57791

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57790 - Billey Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through

PLUGIN Billey

CVE-2026-57790

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57797 - EduMall Plugin

Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduMall: from n/a through

PLUGIN EduMall

CVE-2026-57797

MEDIUM CVSS 4.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57786 - WorkScout-Core Plugin

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through

PLUGIN WorkScout-Core

CVE-2026-57786

HIGH CVSS 8.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57787 - CWS SVGicons Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through

PLUGIN CWS SVGicons

CVE-2026-57787

HIGH CVSS 8.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57789 - Aqua Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through

PLUGIN Aqua

CVE-2026-57789

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57788 - Aalto Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through

PLUGIN Aalto

CVE-2026-57788

HIGH CVSS 7.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57783 - Speaker Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in merkulove Speaker speaker allows Stored XSS.This issue affects Speaker: from n/a through

PLUGIN Speaker

CVE-2026-57783

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57780 - Envision Page Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Envision Envision Page Builder envision-page-builder allows DOM-Based XSS.This issue affects Envision Page Builder: from n/a through

PLUGIN Envision Page Builder

CVE-2026-57780

MEDIUM CVSS 6.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57782 - Universal Clocks Plugin

Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through

PLUGIN Universal Clocks

CVE-2026-57782

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57781 - MeetingHub Plugin

Missing Authorization vulnerability in Sovlix MeetingHub meetinghub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MeetingHub: from n/a through

PLUGIN MeetingHub

CVE-2026-57781

MEDIUM CVSS 5.3 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57770 - Grand Photography Plugin

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through

PLUGIN Grand Photography

CVE-2026-57770

CRITICAL CVSS 9.8 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57772 - WP Inventory Manager Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through

PLUGIN WP Inventory Manager

CVE-2026-57772

HIGH CVSS 8.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57771 - GD Rating System Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through

PLUGIN GD Rating System

CVE-2026-57771

HIGH CVSS 8.5 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57773 - Advanced Shipment Tracking for WooCommerce Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through

PLUGIN Advanced Shipment Tracking for WooCommerce

CVE-2026-57773

HIGH CVSS 7.6 2026-07-13
Threat Entry Updated 2026-07-13

CVE-2026-57779 - Fascinate Plugin

Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through

PLUGIN Fascinate

CVE-2026-57779

MEDIUM CVSS 5.3 2026-07-13
Scroll to top