CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-8897
6.4 MEDIUM

The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 0.1.9.5 due to …

May 27, 2026
CVE-2026-8894
6.4 MEDIUM

The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcode in versions up to, and including, 1.0. This …

May 27, 2026
CVE-2026-8891
6.4 MEDIUM

The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in versions up to, and including, 1.1.0. This is …

May 27, 2026
CVE-2026-8887
6.4 MEDIUM

The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in versions up to, and including, 1.0. This is …

May 27, 2026
CVE-2026-8886
6.4 MEDIUM

The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in versions up to, and including, 1.0. This is due …

May 27, 2026
CVE-2026-8884
6.4 MEDIUM

The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.3.4 due …

May 27, 2026
CVE-2026-8877
6.4 MEDIUM

The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This …

May 27, 2026
CVE-2026-8875
6.4 MEDIUM

The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, …

May 27, 2026
CVE-2026-8873
6.4 MEDIUM

The Content Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 2.4.1 due to …

May 27, 2026
CVE-2026-8872
6.4 MEDIUM

The Animate Your Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animation-set' shortcode in versions up to, and including, 1.0.0. …

May 27, 2026
CVE-2026-8871
6.4 MEDIUM

The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. This is …

May 27, 2026
CVE-2026-8870
6.4 MEDIUM

The Team Master – A Modern WordPress Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up …

May 27, 2026
CVE-2026-8869
6.4 MEDIUM

The Mutual Funds Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in versions up to, and including, 1.2.1. …

May 27, 2026
CVE-2026-8868
6.4 MEDIUM

The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, and including, 1.4. This …

May 27, 2026
CVE-2026-8867
6.4 MEDIUM

The Post Category Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'postcategorygallery' shortcode in versions up to, and including, 1.0.0. …

May 27, 2026
CVE-2026-8866
6.4 MEDIUM

The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This …

May 27, 2026
CVE-2026-8847
6.4 MEDIUM

The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input …

May 27, 2026
CVE-2026-8846
6.4 MEDIUM

The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due …

May 27, 2026
CVE-2026-8845
6.4 MEDIUM

The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is …

May 27, 2026
CVE-2026-8844
6.4 MEDIUM

The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is …

May 27, 2026
CVE-2026-8842
6.4 MEDIUM

The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This …

May 27, 2026
CVE-2026-8837
6.4 MEDIUM

The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up …

May 27, 2026
CVE-2026-8708
4.3 MEDIUM

The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing …

May 27, 2026
CVE-2026-8707
6.1 MEDIUM

The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due …

May 27, 2026
CVE-2026-8703
6.4 MEDIUM

The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to …

May 27, 2026
CVE-2026-8702
6.4 MEDIUM

The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This …

May 27, 2026
CVE-2026-8701
6.4 MEDIUM

The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ticker-typing` shortcodes. This …

May 27, 2026
CVE-2026-8698
6.4 MEDIUM

The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in the …

May 27, 2026
CVE-2026-8048
6.4 MEDIUM

The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions …

May 27, 2026
CVE-2026-8040
6.4 MEDIUM

The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up …

May 27, 2026
CVE-2026-7614
4.3 MEDIUM

The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to …

May 27, 2026
CVE-2026-9236
4.3 MEDIUM

The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in …

May 27, 2026
CVE-2026-6287
5.4 MEDIUM

The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple …

May 27, 2026
CVE-2025-14481
4.3 MEDIUM

The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and including, 26.5. This is due to …

May 27, 2026
CVE-2026-9022
6.4 MEDIUM

The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 …

May 27, 2026
CVE-2026-48999
5.7 MEDIUM

Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts …

May 27, 2026
CVE-2026-2255
4.3 MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the …

May 27, 2026
CVE-2026-2254
6.3 MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related …

May 27, 2026
CVE-2025-15649
5.5 MEDIUM

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and …

May 27, 2026
CVE-2026-9609
4.7 MEDIUM

A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password …

May 27, 2026
CVE-2026-9156
6.5 MEDIUM

Tanium addressed a denial of service vulnerability in Tanium Server.

May 27, 2026
CVE-2026-7493
5.3 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and …

May 27, 2026
CVE-2026-6565
6.4 MEDIUM

The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

May 27, 2026
CVE-2026-9607
6.3 MEDIUM

A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of …

May 27, 2026
CVE-2026-8606
5.9 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to …

May 27, 2026
CVE-2026-9604
4.3 MEDIUM

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results …

May 26, 2026
CVE-2026-8647
4.8 MEDIUM

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the …

May 26, 2026
CVE-2026-46740
5.3 MEDIUM

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated …

May 26, 2026
CVE-2026-9603
6.5 MEDIUM

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of …

May 26, 2026
CVE-2026-48710
6.5 MEDIUM

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because …

May 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.