CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-93954
4.3 MEDIUM

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings …

Sep 19, 2026
CVE-2026-94001
6.5 MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials …

Sep 19, 2026
CVE-2026-94000
6.6 MEDIUM

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints …

Sep 19, 2026
CVE-2026-93999
4.2 MEDIUM

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh …

Sep 19, 2026
CVE-2026-93984
5.3 MEDIUM

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public …

Sep 19, 2026
CVE-2026-93983
5.0 MEDIUM

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted …

Sep 19, 2026
CVE-2026-93981
4.7 MEDIUM

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside …

Sep 19, 2026
CVE-2026-9858
4.3 MEDIUM

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and …

Sep 19, 2026
CVE-2026-9766
4.3 MEDIUM

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the …

Sep 19, 2026
CVE-2026-9613
4.3 MEDIUM

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due …

Sep 19, 2026
CVE-2026-9289
5.3 MEDIUM

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 …

Sep 19, 2026
CVE-2026-8354
6.4 MEDIUM

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, …

Sep 19, 2026
CVE-2026-76579
4.7 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due …

Sep 19, 2026
CVE-2026-5410
6.4 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is …

Sep 19, 2026
CVE-2026-1256
6.4 MEDIUM

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and …

Sep 19, 2026
CVE-2026-18346
5.3 MEDIUM

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not …

Sep 19, 2026
CVE-2026-9855
6.5 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 …

Sep 19, 2026
CVE-2026-9832
5.3 MEDIUM

The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, …

Sep 19, 2026
CVE-2026-9615
4.3 MEDIUM

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() …

Sep 19, 2026
CVE-2026-9232
6.5 MEDIUM

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes …

Sep 19, 2026
CVE-2026-87917
6.1 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data' Dynamic Content Tag in all versions up to, and …

Sep 19, 2026
CVE-2026-7527
4.7 MEDIUM

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and …

Sep 19, 2026
CVE-2026-75959
4.9 MEDIUM

The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filter' parameter in all versions up to, and including, 1.0.36 …

Sep 19, 2026
CVE-2026-6295
4.9 MEDIUM

The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is …

Sep 19, 2026
CVE-2026-5400
6.4 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Media field filter values in versions up to, and including, 4.5.13 …

Sep 19, 2026
CVE-2026-4792
5.3 MEDIUM

The Bread plugin for WordPress is vulnerable to information exposure in versions up to and including 2.9.12. This is due to the lack of authentication …

Sep 19, 2026
CVE-2026-2422
6.4 MEDIUM

The WP Composer – The Easiest Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pbwp_raw_shortcode' shortcode in all versions up …

Sep 19, 2026
CVE-2026-2278
4.3 MEDIUM

The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in …

Sep 19, 2026
CVE-2026-1984
5.3 MEDIUM

The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' …

Sep 19, 2026
CVE-2026-1641
6.5 MEDIUM

The Wow Elements Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.11.2. This is …

Sep 19, 2026
CVE-2026-1242
4.3 MEDIUM

The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, …

Sep 19, 2026
CVE-2026-15947
4.3 MEDIUM

The Metasync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_instant_indexing_settings() function in versions up …

Sep 19, 2026
CVE-2026-15946
4.3 MEDIUM

The Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization plugin for WordPress is vulnerable to authorization bypass in …

Sep 19, 2026
CVE-2026-15463
6.1 MEDIUM

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'host' parameter in all …

Sep 19, 2026
CVE-2026-15098
6.4 MEDIUM

The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) …

Sep 19, 2026
CVE-2026-13770
6.4 MEDIUM

The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 19, 2026
CVE-2026-13200
6.5 MEDIUM

The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 2.5.3 due to …

Sep 19, 2026
CVE-2026-13191
6.5 MEDIUM

The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 2.5.3 due to …

Sep 19, 2026
CVE-2026-12402
4.4 MEDIUM

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, …

Sep 19, 2026
CVE-2026-11899
4.3 MEDIUM

The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Sep 19, 2026
CVE-2026-11608
6.1 MEDIUM

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 …

Sep 19, 2026
CVE-2026-92435
5.3 MEDIUM

The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several …

Sep 19, 2026
CVE-2026-92430
5.3 MEDIUM

The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7 does not verify the authenticity of its PIX payment …

Sep 19, 2026
CVE-2026-92425
5.5 MEDIUM

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, …

Sep 19, 2026
CVE-2026-92421
4.7 MEDIUM

The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the …

Sep 19, 2026
CVE-2026-92099
6.5 MEDIUM

The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a …

Sep 19, 2026
CVE-2026-91847
4.8 MEDIUM

The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its …

Sep 19, 2026
CVE-2026-84750
6.5 MEDIUM

The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or extension of files uploaded through one of its …

Sep 19, 2026
CVE-2026-19860
5.5 MEDIUM

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation …

Sep 19, 2026
CVE-2026-16557
4.3 MEDIUM

The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check when returning page-builder content through an authenticated AJAX action, allowing any …

Sep 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.