CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-27382

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro metro allows DOM-Based XSS.This issue affects Metro: from n/a through <= 2.13.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27381

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Aora aora allows PHP Local File Inclusion.This issue affects Aora: from n/a through <= 1.3.15.

    Published: 5 Mar 2026
    8.8
    High

    CVE-2026-27379

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27376

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Claue - Clean, Minimal Elementor WooCommerce Theme claue allows Reflected XSS.This issue affects Claue - Clean, Minimal Elementor WooCommerce Theme: from n/a through <= 2.2.7.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27375

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Gecko gecko allows Reflected XSS.This issue affects Gecko: from n/a through <= 1.9.8.

    Published: 5 Mar 2026
    7.5
    High

    CVE-2026-27374

    Last Modified: 22 Apr 2026

    Missing Authorization vulnerability in vanquish WooCommerce Order Details woocommerce-order-details allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Order Details: from n/a through <= 3.1.

    Published: 5 Mar 2026
    8.5
    High

    CVE-2026-27373

    Last Modified: 22 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome tablesome allows Blind SQL Injection.This issue affects Tablesome: from n/a through <= 1.2.3.

    Published: 5 Mar 2026
    7.5
    High

    CVE-2026-27370

    Last Modified: 22 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Premio Chaty chaty allows Retrieve Embedded Sensitive Data.This issue affects Chaty: from n/a through <= 3.5.1.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27369

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in BoldThemes Celeste celeste allows Object Injection.This issue affects Celeste: from n/a through <= 1.3.6.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27367

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through < 3.4.5.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27363

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Stored XSS.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6.

    Published: 5 Mar 2026
    6.5
    Medium

    CVE-2026-27362

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Bakery Autoresponder Addon: from n/a through <= 1.0.6.

    Published: 5 Mar 2026
    7.5
    High

    CVE-2026-27361

    Last Modified: 22 Apr 2026

    Missing Authorization vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.1.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27359

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fox-themes Awa Plugins awa-plugins allows Reflected XSS.This issue affects Awa Plugins: from n/a through <= 1.4.4.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27358

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Architecturer architecturer allows Reflected XSS.This issue affects Architecturer: from n/a through < 3.9.5.

    Published: 5 Mar 2026
    6.5
    Medium

    CVE-2026-27354

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace WooCommerce Coming Soon Product with Countdown woo-coming-soon-product allows Stored XSS.This issue affects WooCommerce Coming Soon Product with Countdown: from n/a through <= 5.0.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27353

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand News grandnews allows Reflected XSS.This issue affects Grand News: from n/a through <= 3.4.3.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27352

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Starto starto allows Reflected XSS.This issue affects Starto: from n/a through < 2.2.5.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27348

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows DOM-Based XSS.This issue affects Photography: from n/a through < 7.7.6.

    Published: 5 Mar 2026
    5.9
    Medium

    CVE-2026-27344

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects inseri core: from n/a through <= 1.0.5.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27342

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopFit - Fitness and Gym WordPress Theme topfit allows PHP Local File Inclusion.This issue affects TopFit - Fitness and Gym WordPress Theme: from n/a through <= 1.9.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27341

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes TopScorer - Sports WordPress Theme topscorer allows PHP Local File Inclusion.This issue affects TopScorer - Sports WordPress Theme: from n/a through <= 1.2.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27340

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Apollo | Night Club, DJ Event WordPress Theme apollo allows PHP Local File Inclusion.This issue affects Apollo | Night Club, DJ Event WordPress Theme: from n/a through <= 1.3.1.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27339

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Buzz Stone | Magazine & Viral Blog WordPress Theme buzzstone allows PHP Local File Inclusion.This issue affects Buzz Stone | Magazine & Viral Blog WordPress Theme: from n/a through <= 1.0.2.

    Published: 5 Mar 2026
    8.8
    High

    CVE-2026-27338

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in AivahThemes Car Zone carzone allows Object Injection.This issue affects Car Zone: from n/a through <= 3.7.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27337

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Chronicle - Lifestyle Magazine & Blog WordPress Theme chronicle allows PHP Local File Inclusion.This issue affects Chronicle - Lifestyle Magazine & Blog WordPress Theme: from n/a through <= 1.0.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27336

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Consultor | Consulting, Accounting & Legal Counsel WordPress Theme consultor allows PHP Local File Inclusion.This issue affects Consultor | Consulting, Accounting & Legal Counsel WordPress Theme: from n/a through <= 1.2.4.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27335

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Ekoterra - NonProfit, Green Energy & Ecology Theme ekoterra allows PHP Local File Inclusion.This issue affects Ekoterra - NonProfit, Green Energy & Ecology Theme: from n/a through <= 1.0.0.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27334

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in dan_fisher Alchemists alchemists allows PHP Local File Inclusion.This issue affects Alchemists: from n/a through <= 4.6.0.

    Published: 5 Mar 2026
    7.1
    High

    CVE-2026-27332

    Last Modified: 22 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Agrofood agrofood allows Reflected XSS.This issue affects Agrofood: from n/a through < 1.4.0.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27326

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme: from n/a through <= 1.2.5.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27098

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in axiomthemes Au Pair Agency - Babysitting & Nanny Theme au-pair-agency allows Object Injection.This issue affects Au Pair Agency - Babysitting & Nanny Theme: from n/a through <= 1.2.2.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-27097

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes CasaMia | Property Rental Real Estate WordPress Theme casamia allows PHP Local File Inclusion.This issue affects CasaMia | Property Rental Real Estate WordPress Theme: from n/a through <= 1.1.2.

    Published: 5 Mar 2026
    7.2
    High

    CVE-2026-24963

    Last Modified: 22 Apr 2026

    Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.

    Published: 5 Mar 2026
    9.9
    Critical

    CVE-2026-24960

    Last Modified: 22 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files.This issue affects Charety: from n/a through < 2.0.2.

    Published: 5 Mar 2026
    7.5
    High

    CVE-2026-24385

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1.

    Published: 5 Mar 2026
    9.1
    Critical

    CVE-2026-23802

    Last Modified: 22 Apr 2026

    Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious Files.This issue affects AI Engine: from n/a through <= 3.3.2.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-23801

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes The Issue theissue allows PHP Local File Inclusion.This issue affects The Issue: from n/a through <= 1.6.11.

    Published: 5 Mar 2026
    6.5
    Medium

    CVE-2026-23799

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.5.

    Published: 5 Mar 2026
    8.8
    High

    CVE-2026-23798

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in blubrry PowerPress Podcasting powerpress allows Object Injection.This issue affects PowerPress Podcasting: from n/a through <= 11.15.10.

    Published: 5 Mar 2026
    6.5
    Medium

    CVE-2026-23546

    Last Modified: 22 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing allows Retrieve Embedded Sensitive Data.This issue affects Classified Listing: from n/a through <= 5.3.4.

    Published: 5 Mar 2026
    9.8
    Critical

    CVE-2026-22501

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue affects Mounthood: from n/a through <= 1.3.2.

    Published: 5 Mar 2026
    9.8
    Critical

    CVE-2026-22497

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects Jardi: from n/a through <= 1.7.2.

    Published: 5 Mar 2026
    7.5
    High

    CVE-2026-22479

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in ThemeRuby Easy Post Submission easy-post-submission allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Post Submission: from n/a through <= 2.4.0.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-22478

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes FindAll findall allows PHP Local File Inclusion.This issue affects FindAll: from n/a through <= 1.4.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-22477

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Felizia felizia allows PHP Local File Inclusion.This issue affects Felizia: from n/a through <= 1.3.4.

    Published: 5 Mar 2026
    8.1
    High

    CVE-2026-22476

    Last Modified: 22 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Etchy etchy allows PHP Local File Inclusion.This issue affects Etchy: from n/a through <= 1.0.

    Published: 5 Mar 2026
    9.8
    Critical

    CVE-2026-22475

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4.

    Published: 5 Mar 2026
    9.8
    Critical

    CVE-2026-22474

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection.This issue affects Equestrian Centre: from n/a through <= 1.5.

    Published: 5 Mar 2026
    8.8
    High

    CVE-2026-22473

    Last Modified: 22 Apr 2026

    Deserialization of Untrusted Data vulnerability in designthemes Dental Clinic dental allows Object Injection.This issue affects Dental Clinic: from n/a through <= 3.7.

    Published: 5 Mar 2026