| CVE-2026-11804 |
Program Module Vulnerability |
23.07.2026 |
5.2 |
| CVE-2026-16584 |
AWS API MCP Server Security Policy Bypass via Startup Failure |
23.07.2026 |
7 |
| CVE-2026-48530 |
GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx |
23.07.2026 |
|
| CVE-2026-48531 |
GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx |
23.07.2026 |
|
| CVE-2026-48532 |
GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx |
23.07.2026 |
|
| CVE-2026-48533 |
|
23.07.2026 |
|
| CVE-2026-48534 |
GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx |
23.07.2026 |
|
| CVE-2026-48535 |
GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx |
23.07.2026 |
|
| CVE-2026-48536 |
GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx |
23.07.2026 |
|
| CVE-2026-48537 |
GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx |
23.07.2026 |
|
| CVE-2026-48538 |
GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx |
23.07.2026 |
|
| CVE-2026-48539 |
GFI Archiver < 15.13 Stored XSS via MailInsights.aspx |
23.07.2026 |
|
| CVE-2026-43820 |
|
23.07.2026 |
|
| CVE-2026-43823 |
|
23.07.2026 |
|
| CVE-2026-16733 |
bahmutov find-cypress-specs Branch index.js shell.exec os command injection |
23.07.2026 |
|
| CVE-2026-16735 |
release-it conventional-changelog Changelog File index.js writeChangelog os command injection |
23.07.2026 |
|
| CVE-2026-65687 |
Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing |
23.07.2026 |
|
| CVE-2026-65688 |
Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Font Processing |
23.07.2026 |
|
| CVE-2026-65689 |
Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via Database Download |
23.07.2026 |
|
| CVE-2026-65690 |
Bold Reports Standalone Report Designer 14.1.12 Path Traversal RCE via File Upload |
23.07.2026 |
|
| CVE-2026-8287 |
Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software |
23.07.2026 |
4.3 |
| CVE-2026-14257 |
brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash |
23.07.2026 |
7.5 |
| CVE-2026-65898 |
DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig |
23.07.2026 |
|
| CVE-2026-65899 |
DOMPurify before 3.4.9 Trusted Types Policy State Contamination |
23.07.2026 |
|
| CVE-2026-65900 |
DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM |
23.07.2026 |
|
| CVE-2026-65901 |
DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName |
23.07.2026 |
|
| CVE-2026-65902 |
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags |
23.07.2026 |
|
| CVE-2026-65903 |
DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS |
23.07.2026 |
|
| CVE-2026-65904 |
DOMPurify before 3.4.4 Cross-Site Scripting via IN_PLACE mode |
23.07.2026 |
|
| CVE-2026-65911 |
DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage |
23.07.2026 |
|
| CVE-2026-65912 |
DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR |
23.07.2026 |
|
| CVE-2026-65913 |
DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES |
23.07.2026 |
|
| CVE-2026-65914 |
DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization |
23.07.2026 |
|
| CVE-2026-15037 |
XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization |
23.07.2026 |
|
| CVE-2026-65906 |
|
23.07.2026 |
8.8 |
| CVE-2026-65907 |
|
23.07.2026 |
9.1 |
| CVE-2026-65908 |
|
23.07.2026 |
8.6 |
| CVE-2026-57626 |
WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-61945 |
WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-64800 |
|
23.07.2026 |
3.5 |
| CVE-2026-64802 |
|
23.07.2026 |
7.8 |
| CVE-2026-64803 |
|
23.07.2026 |
7.8 |
| CVE-2026-64804 |
|
23.07.2026 |
8.4 |
| CVE-2026-64805 |
|
23.07.2026 |
8.4 |
| CVE-2026-64806 |
|
23.07.2026 |
8.4 |
| CVE-2026-64807 |
|
23.07.2026 |
7.8 |
| CVE-2026-64808 |
|
23.07.2026 |
8.4 |
| CVE-2026-64809 |
|
23.07.2026 |
8.4 |
| CVE-2026-64810 |
|
23.07.2026 |
4.3 |
| CVE-2026-64811 |
|
23.07.2026 |
7.8 |
| CVE-2026-64812 |
|
23.07.2026 |
10 |
| CVE-2026-64813 |
|
23.07.2026 |
10 |
| CVE-2026-64814 |
|
23.07.2026 |
8.6 |
| CVE-2026-64815 |
|
23.07.2026 |
8.1 |
| CVE-2026-65475 |
WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65605 |
SiYuan before v3.7.2 Stored XSS to RCE via Attribute View |
23.07.2026 |
|
| CVE-2026-65606 |
SiYuan before v3.7.2 Cross-Site Scripting to RCE |
23.07.2026 |
|
| CVE-2026-65607 |
SiYuan before v3.7.2 Path Traversal via /export/temp/ |
23.07.2026 |
|
| CVE-2026-65608 |
Grav before 2.0.9 Remote Code Execution via FlexDirectory |
23.07.2026 |
|
| CVE-2026-65895 |
Grav API Plugin before 1.0.10 Broken Access Control |
23.07.2026 |
|
| CVE-2026-65896 |
Grav API Plugin before 1.0.10 Path Traversal via move |
23.07.2026 |
|
| CVE-2026-65897 |
Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups |
23.07.2026 |
|
| CVE-2025-68081 |
WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
5.9 |
| CVE-2026-24537 |
WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-24552 |
WordPress Create by Mediavine plugin <= 2.5.3 - SQL Injection vulnerability |
23.07.2026 |
8.5 |
| CVE-2026-24628 |
WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
5.9 |
| CVE-2026-24639 |
WordPress Photo Block plugin <= 1.7.1 - Server Side Request Forgery (SSRF) vulnerability |
23.07.2026 |
4.4 |
| CVE-2026-25405 |
WordPress eRoom plugin <= 1.7.1 - SQL Injection vulnerability |
23.07.2026 |
8.5 |
| CVE-2026-25424 |
WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-25427 |
WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-25466 |
WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-27064 |
WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability |
23.07.2026 |
9.1 |
| CVE-2026-27355 |
WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-27372 |
WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-27377 |
WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control vulnerability |
23.07.2026 |
6.7 |
| CVE-2026-27391 |
WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-27392 |
WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-27399 |
WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-27403 |
WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-27418 |
WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-27422 |
WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-27423 |
WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-57367 |
WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57370 |
WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflected Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57373 |
WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.4 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-57374 |
WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.7 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57384 |
WordPress WishList Member X plugin <= 3.32.0 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-57397 |
WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57425 |
WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-57427 |
WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57428 |
WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57696 |
WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57699 |
WordPress Slider Pro plugin <= 4.8.13 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57701 |
WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57703 |
WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerability |
23.07.2026 |
6.3 |
| CVE-2026-57704 |
WordPress Smart Manager plugin <= 8.90.0 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57716 |
WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-57717 |
WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-57735 |
WordPress Breakdance plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57767 |
WordPress WP Google Maps Pro plugin <= 10.1.02 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57769 |
WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-57784 |
WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
9.6 |
| CVE-2026-57785 |
WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
8.8 |
| CVE-2026-57808 |
WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-57809 |
WordPress AffiliateWP plugin <= 2.34.0 - Reflected Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-59512 |
WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-59513 |
WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-59514 |
WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-59517 |
WordPress Easy Form Builder plugin <= 4.0.12 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-59522 |
WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-59524 |
WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-59525 |
WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-59526 |
WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-59540 |
WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability |
23.07.2026 |
9.8 |
| CVE-2026-59541 |
WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability |
23.07.2026 |
8.8 |
| CVE-2026-59542 |
WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability |
23.07.2026 |
7.7 |
| CVE-2026-59543 |
WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability |
23.07.2026 |
9.9 |
| CVE-2026-59544 |
WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability |
23.07.2026 |
9.8 |
| CVE-2026-59545 |
WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability |
23.07.2026 |
8.1 |
| CVE-2026-59547 |
WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken Access Control vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-59554 |
WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-59555 |
WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability |
23.07.2026 |
10 |
| CVE-2026-61943 |
WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-61944 |
WordPress Bookly plugin <= 27.7 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-61946 |
WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-61947 |
WordPress Form Vibes – Database Manager for Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-61948 |
WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-61949 |
WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-61950 |
WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability |
23.07.2026 |
9.3 |
| CVE-2026-61951 |
WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability |
23.07.2026 |
9.8 |
| CVE-2026-61954 |
WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-61972 |
WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-61973 |
WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-61981 |
WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-65449 |
WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65450 |
WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
23.07.2026 |
8.5 |
| CVE-2026-65451 |
WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability |
23.07.2026 |
8.5 |
| CVE-2026-65452 |
WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65453 |
WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65454 |
WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability |
23.07.2026 |
8.5 |
| CVE-2026-65455 |
WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability |
23.07.2026 |
9.1 |
| CVE-2026-65456 |
WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65457 |
WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65458 |
WordPress Polylang plugin <= 3.8.5 - Sensitive Data Exposure vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65460 |
WordPress Zarinpal Gateway plugin <= 5.1.0 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65461 |
WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability |
23.07.2026 |
9.1 |
| CVE-2026-65462 |
WordPress Uncanny Automator plugin <= 7.3.2 - SQL Injection vulnerability |
23.07.2026 |
7.6 |
| CVE-2026-65463 |
WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-65464 |
WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-65465 |
WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65466 |
WordPress JetBooking plugin <= 4.1.2 - Server Side Request Forgery (SSRF) vulnerability |
23.07.2026 |
4.9 |
| CVE-2026-65467 |
WordPress JetEngine plugin <= 3.8.11 - Server Side Request Forgery (SSRF) vulnerability |
23.07.2026 |
4.9 |
| CVE-2026-65468 |
WordPress JetBooking plugin <= 4.1.2 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65469 |
WordPress AWP Classifieds plugin <= 4.4.7 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65470 |
WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65471 |
WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
9.6 |
| CVE-2026-65472 |
WordPress Kit (formerly ConvertKit) plugin <= 3.3.5 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65473 |
WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65474 |
WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65476 |
WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65477 |
WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-65478 |
WordPress ListingPro plugin <= 2.9.10 - Broken Access Control vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-65479 |
WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-65480 |
WordPress TheGem theme <= 5.11.1 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65481 |
WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-65482 |
WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65483 |
WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
5.9 |
| CVE-2026-65484 |
WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability |
23.07.2026 |
6.3 |
| CVE-2026-65485 |
WordPress Content Control plugin <= 2.6.5 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65486 |
WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65487 |
WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65488 |
WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65489 |
WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65490 |
WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65491 |
WordPress Query Wrangler plugin <= 1.5.57 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65492 |
WordPress Dokan Pro plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65493 |
WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-65494 |
WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65495 |
WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-65496 |
WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vulnerability |
23.07.2026 |
4.4 |
| CVE-2026-65497 |
WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability |
23.07.2026 |
7.2 |
| CVE-2026-65498 |
WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65499 |
WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Broken Access Control vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65500 |
WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Broken Access Control vulnerability |
23.07.2026 |
7.5 |
| CVE-2026-65501 |
WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object References (IDOR) vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65503 |
WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65505 |
WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Data Exposure vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65506 |
WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.12 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65510 |
WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65511 |
WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65512 |
WordPress WP Activity Log plugin <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
5.4 |
| CVE-2026-65514 |
WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65516 |
WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerability |
23.07.2026 |
7.2 |
| CVE-2026-65518 |
WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65519 |
WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65521 |
WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65522 |
WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65524 |
WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65525 |
WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65526 |
WordPress Visualizer plugin <= 4.0.6 - SQL Injection vulnerability |
23.07.2026 |
8.5 |
| CVE-2026-65527 |
WordPress LIQUID SPEECH BALLOON plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65528 |
WordPress BSK PDF Manager plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65529 |
WordPress Graphina plugin <= 3.1.12 - Broken Access Control vulnerability |
23.07.2026 |
5.3 |
| CVE-2026-65530 |
WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65531 |
WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability |
23.07.2026 |
4.8 |
| CVE-2026-65532 |
WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability |
23.07.2026 |
7.6 |
| CVE-2026-65533 |
WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65534 |
WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
5.9 |
| CVE-2026-65535 |
WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65536 |
WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
6.5 |
| CVE-2026-65537 |
WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability |
23.07.2026 |
4.3 |
| CVE-2026-65538 |
WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
5.9 |
| CVE-2026-65539 |
WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65540 |
WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) vulnerability |
23.07.2026 |
7.1 |
| CVE-2026-65550 |
WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability |
23.07.2026 |
5.9 |
| CVE-2026-16745 |
Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation |
23.07.2026 |
|
| CVE-2026-64611 |
Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel() |
23.07.2026 |
|
| CVE-2026-13009 |
AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter |
23.07.2026 |
6.5 |
| CVE-2026-13119 |
Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter |
23.07.2026 |
6.5 |
| CVE-2026-15015 |
MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint |
23.07.2026 |
9.8 |
| CVE-2026-15017 |
MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers |
23.07.2026 |
8.8 |
| CVE-2026-15348 |
Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter |
23.07.2026 |
6.3 |
| CVE-2026-15394 |
Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta |
23.07.2026 |
6.4 |
| CVE-2026-15448 |
Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter |
23.07.2026 |
6.5 |
| CVE-2026-15786 |
WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter |
23.07.2026 |
4.9 |
| CVE-2026-65758 |
Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 |
23.07.2026 |
|
| CVE-2026-14282 |
GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field |
23.07.2026 |
9.8 |
| CVE-2026-14481 |
Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter |
23.07.2026 |
6.4 |
| CVE-2026-15011 |
Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter |
23.07.2026 |
9.8 |
| CVE-2026-15404 |
Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title |
23.07.2026 |
6.4 |
| CVE-2026-15646 |
Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute |
23.07.2026 |
6.4 |
| CVE-2026-15647 |
Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field |
23.07.2026 |
4.4 |
| CVE-2026-15761 |
Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter |
23.07.2026 |
6.5 |
| CVE-2026-15794 |
Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute |
23.07.2026 |
6.4 |
| CVE-2026-15827 |
GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints |
23.07.2026 |
5.3 |
| CVE-2026-15906 |
Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter |
23.07.2026 |
6.5 |
| CVE-2026-16078 |
WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter |
23.07.2026 |
6.5 |
| CVE-2026-64799 |
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions |
23.07.2026 |
|
| CVE-2026-64871 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension |
23.07.2026 |
|
| CVE-2026-64872 |
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension |
23.07.2026 |
|
| CVE-2026-64873 |
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension |
23.07.2026 |
|
| CVE-2026-64874 |
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension |
23.07.2026 |
|
| CVE-2026-64875 |
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension |
23.07.2026 |
|
| CVE-2026-64876 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension |
23.07.2026 |
|
| CVE-2026-65430 |
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension |
23.07.2026 |
|
| CVE-2026-65431 |
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension |
23.07.2026 |
|
| CVE-2026-65712 |
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension |
23.07.2026 |
|
| CVE-2026-65713 |
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension |
23.07.2026 |
|
| CVE-2026-65754 |
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension |
23.07.2026 |
|
| CVE-2026-65755 |
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension |
23.07.2026 |
|
| CVE-2026-65756 |
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension |
23.07.2026 |
|
| CVE-2026-65757 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension |
23.07.2026 |
|
| CVE-2024-58023 |
|
23.07.2026 |
8.4 |
| CVE-2024-58330 |
|
23.07.2026 |
7.5 |
| CVE-2026-16287 |
Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update |
23.07.2026 |
7.8 |
| CVE-2026-16723 |
Remote Code Execution in fastjson 1.2.68–1.2.83 |
23.07.2026 |
9 |
| CVE-2026-52684 |
Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack |
23.07.2026 |
3.7 |
| CVE-2026-52686 |
Wildcard CNAME proof validation bypass |
23.07.2026 |
3.7 |
| CVE-2026-52688 |
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation |
23.07.2026 |
7.5 |
| CVE-2026-12421 |
ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values |
23.07.2026 |
7.2 |
| CVE-2026-59677 |
Process Kill Attack Vector in killall() in seunshare |
23.07.2026 |
|
| CVE-2026-59678 |
portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager |
23.07.2026 |
|
| CVE-2026-9635 |
WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute |
23.07.2026 |
6.4 |
| CVE-2026-9713 |
Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload |
23.07.2026 |
7.5 |
| CVE-2026-9729 |
Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter |
23.07.2026 |
6.4 |
| CVE-2026-12082 |
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure) |
23.07.2026 |
|
| CVE-2026-14291 |
Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa |
23.07.2026 |
|
| CVE-2026-59676 |
Local File Deletion Attack Vector in rm_rf() in seunshare |
23.07.2026 |
|
| CVE-2026-9066 |
WP Compress < 7.10.04 - Reflected XSS via test_zone |
23.07.2026 |
|
| CVE-2026-9577 |
Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter |
23.07.2026 |
|
| CVE-2026-63226 |
|
23.07.2026 |
|
| CVE-2026-64600 |
xfs: resample the data fork mapping after cycling ILOCK |
23.07.2026 |
|
| CVE-2026-7232 |
FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters |
23.07.2026 |
7.2 |
| CVE-2026-7534 |
SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter |
23.07.2026 |
7.2 |
| CVE-2026-6390 |
Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling. |
23.07.2026 |
|
| CVE-2026-15074 |
@fastify/static vulnerable to route guard bypass via path traversal |
23.07.2026 |
7.5 |
| CVE-2026-7120 |
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths |
23.07.2026 |
5.3 |
| CVE-2026-21723 |
CVE-2026-21723 Record |
23.07.2026 |
5.3 |
| CVE-2026-16653 |
boazsegev facil.io Public Folder http.c http_sendfile2 path traversal |
23.07.2026 |
|
| CVE-2026-16631 |
publint package-manager pack.js child_process.exec os command injection |
23.07.2026 |
|
| CVE-2026-16632 |
boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation |
23.07.2026 |
|
| CVE-2026-16630 |
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection |
23.07.2026 |
|
| CVE-2026-38763 |
|
22.07.2026 |
|
| CVE-2026-38765 |
|
22.07.2026 |
|
| CVE-2026-38766 |
|
22.07.2026 |
|
| CVE-2026-60366 |
|
23.07.2026 |
10 |
| CVE-2026-60367 |
|
23.07.2026 |
9.8 |
| CVE-2026-60368 |
|
23.07.2026 |
8.8 |
| CVE-2026-60369 |
|
23.07.2026 |
9.9 |
| CVE-2026-60370 |
|
23.07.2026 |
7.5 |
| CVE-2026-60371 |
|
23.07.2026 |
8 |
| CVE-2026-60372 |
|
23.07.2026 |
9.8 |
| CVE-2026-60373 |
|
23.07.2026 |
8.8 |
| CVE-2026-60439 |
|
23.07.2026 |
8.8 |
| CVE-2026-60455 |
|
23.07.2026 |
8.8 |
| CVE-2026-61246 |
|
23.07.2026 |
8.8 |
| CVE-2026-16628 |
oclif JIT Plugin Entry child_process.exec os command injection |
23.07.2026 |
|
| CVE-2026-16629 |
danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection |
22.07.2026 |
|
| CVE-2025-50330 |
|
22.07.2026 |
|
| CVE-2025-60835 |
|
22.07.2026 |
|
| CVE-2026-13089 |
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify |
22.07.2026 |
|
| CVE-2026-63265 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints |
23.07.2026 |
|
| CVE-2026-63280 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager |
23.07.2026 |
|
| CVE-2026-63281 |
Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager |
23.07.2026 |
|
| CVE-2026-63683 |
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager |
23.07.2026 |
|
| CVE-2026-63684 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension |
23.07.2026 |
|
| CVE-2026-63685 |
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension |
23.07.2026 |
|
| CVE-2026-64791 |
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager |
23.07.2026 |
|
| CVE-2026-64792 |
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions |
23.07.2026 |
|
| CVE-2026-64793 |
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions |
23.07.2026 |
|
| CVE-2026-64794 |
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions |
23.07.2026 |
|
| CVE-2026-64795 |
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions |
23.07.2026 |
|
| CVE-2026-64796 |
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension |
23.07.2026 |
|
| CVE-2026-64797 |
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension |
23.07.2026 |
|
| CVE-2026-64798 |
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension |
23.07.2026 |
|
| CVE-2025-44089 |
|
22.07.2026 |
|
| CVE-2025-44090 |
|
22.07.2026 |
|
| CVE-2025-50324 |
|
22.07.2026 |
|
| CVE-2025-50325 |
|
22.07.2026 |
|
| CVE-2025-50327 |
|
22.07.2026 |
|
| CVE-2025-50329 |
|
22.07.2026 |
|
| CVE-2026-64829 |
Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow |
23.07.2026 |
|