CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2018-25132

    Last Modified: 9 Apr 2026

    MyBB Trending Widget Plugin 1.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through thread titles. Attackers can modify thread titles with script payloads that will execute when other users view the trending widget.

    Published: 23 Jan 2026
    5.1
    Medium

    CVE-2018-25116

    Last Modified: 9 Apr 2026

    MyBB Thread Redirect Plugin 0.2.1 contains a cross-site scripting vulnerability in the custom text input field for thread redirects. Attackers can inject malicious SVG scripts that will execute when other users view the thread, allowing arbitrary script execution.

    Published: 23 Jan 2026
    5.1
    Medium

    CVE-2025-71177

    Last Modified: 5 Mar 2026

    LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper output encoding in package search results. When other users view search results that include the malicious package, the injected script executes in their browsers, potentially enabling session hijacking, credential theft, and unauthorized actions in the context of the victim.

    Published: 23 Jan 2026
    6
    Medium

    CVE-2026-1299

    Last Modified: 16 Apr 2026

    The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24646

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24647

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24648

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24649

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24642

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24643

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24644

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24645

    Last Modified: 24 Jan 2026

    Not used

    Published: 23 Jan 2026
    8.2
    High

    CVE-2026-0994

    Last Modified: 1 Sept 2026

    A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling logic, an attacker can supply deeply nested Any structures that bypass the intended recursion limit, eventually exhausting Python’s recursion stack and causing a RecursionError.

    Published: 23 Jan 2026
    4.3
    Medium

    CVE-2026-24636

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sugar Calendar (Lite): from n/a through <= 3.9.1.

    Published: 23 Jan 2026
    7.5
    High

    CVE-2026-24635

    Last Modified: 16 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edublink-core allows PHP Local File Inclusion.This issue affects EduBlink Core: from n/a through <= 2.0.7.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24634

    Last Modified: 16 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Reviews: from n/a through <= 3.2.16.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24633

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Add Expires Headers & Optimized Minify: from n/a through <= 3.2.0.

    Published: 23 Jan 2026
    5.9
    Medium

    CVE-2026-24632

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jagdish1o1 Delay Redirects delay-redirects allows DOM-Based XSS.This issue affects Delay Redirects: from n/a through <= 1.0.0.

    Published: 23 Jan 2026
    5.4
    Medium

    CVE-2026-24631

    Last Modified: 24 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rosebud: from n/a through <= 1.4.

    Published: 23 Jan 2026
    6.5
    Medium

    CVE-2026-24630

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Design Stylish Cost Calculator stylish-cost-calculator allows Stored XSS.This issue affects Stylish Cost Calculator: from n/a through <= 8.2.9.

    Published: 23 Jan 2026
    5.9
    Medium

    CVE-2026-24629

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ability, Inc Web Accessibility with Max Access accessibility-toolbar allows Stored XSS.This issue affects Web Accessibility with Max Access: from n/a through <= 2.1.0.

    Published: 23 Jan 2026
    4.3
    Medium

    CVE-2026-24627

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Trusona Trusona for WordPress trusona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trusona for WordPress: from n/a through <= 2.0.0.

    Published: 23 Jan 2026
    5.9
    Medium

    CVE-2026-24626

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Logo Slider logo-slider-wp allows Stored XSS.This issue affects Logo Slider: from n/a through <= 5.1.1.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24625

    Last Modified: 18 Apr 2026

    Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3.

    Published: 23 Jan 2026
    7.6
    High

    CVE-2026-24624

    Last Modified: 28 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL Injection.This issue affects Neoforum: from n/a through <= 1.0.

    Published: 23 Jan 2026
    7.1
    High

    CVE-2026-24623

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saeros1984 Neoforum neoforum allows Reflected XSS.This issue affects Neoforum: from n/a through <= 1.0.

    Published: 23 Jan 2026
    5.4
    Medium

    CVE-2026-24622

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Sergiy Dzysyak Suggestion Toolkit suggestion-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Suggestion Toolkit: from n/a through <= 5.0.

    Published: 23 Jan 2026
    5.9
    Medium

    CVE-2026-24621

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Statsenko Terms descriptions terms-descriptions allows DOM-Based XSS.This issue affects Terms descriptions: from n/a through <= 3.4.9.

    Published: 23 Jan 2026
    5.9
    Medium

    CVE-2026-24620

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue affects Landing Page Builder: from n/a through <= 1.5.3.4.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24619

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in PopCash PopCash.Net Code Integration Tool popcashnet-code-integration-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PopCash.Net Code Integration Tool: from n/a through <= 1.8.

    Published: 23 Jan 2026
    6.5
    Medium

    CVE-2026-24617

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Easy Modal easy-modal allows Stored XSS.This issue affects Easy Modal: from n/a through <= 2.1.0.

    Published: 23 Jan 2026
    6.5
    Medium

    CVE-2026-24616

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Popups: from n/a through <= 2.2.0.5.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24615

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in themebeez Cream Magazine cream-magazine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cream Magazine: from n/a through <= 2.1.10.

    Published: 23 Jan 2026
    5.9
    Medium

    CVE-2026-24614

    Last Modified: 16 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.10.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24613

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.6.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24612

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in themebeez Orchid Store orchid-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Orchid Store: from n/a through <= 1.5.15.

    Published: 23 Jan 2026
    7.5
    High

    CVE-2026-24609

    Last Modified: 16 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclusion.This issue affects Laurent: from n/a through <= 3.1.

    Published: 23 Jan 2026
    7.5
    High

    CVE-2026-24608

    Last Modified: 16 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core laurent-core allows PHP Local File Inclusion.This issue affects Laurent Core: from n/a through <= 2.4.1.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24607

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in wptravelengine Travel Monster travel-monster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Monster: from n/a through <= 1.3.3.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24606

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through <= 4.3.13.

    Published: 23 Jan 2026
    4.3
    Medium

    CVE-2026-24605

    Last Modified: 16 Apr 2026

    Missing Authorization vulnerability in pencilwp X Addons for Elementor x-addons-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects X Addons for Elementor: from n/a through <= 1.0.23.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24604

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in themebeez Simple GDPR Cookie Compliance simple-gdpr-cookie-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple GDPR Cookie Compliance: from n/a through <= 2.0.0.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24603

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in themebeez Universal Google Adsense and Ads manager universal-google-adsense-and-ads-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Google Adsense and Ads manager: from n/a through <= 1.1.8.

    Published: 23 Jan 2026
    Unknown

    CVE-2026-24602

    Last Modified: 4 Feb 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This is a false positive. According to the vendor, the function identified as a vulnerability is intentional and part of the expected design.

    Published: 23 Jan 2026
    6.5
    Medium

    CVE-2026-24601

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Pay Writer penci-pay-writer allows Stored XSS.This issue affects Penci Pay Writer: from n/a through <= 1.5.

    Published: 23 Jan 2026
    6.5
    Medium

    CVE-2026-24600

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Review penci-review allows Stored XSS.This issue affects Penci Review: from n/a through <= 3.5.

    Published: 23 Jan 2026
    5.3
    Medium

    CVE-2026-24599

    Last Modified: 16 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0.

    Published: 23 Jan 2026
    4.3
    Medium

    CVE-2026-24598

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in bestwebsoft Multilanguage by BestWebSoft multilanguage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multilanguage by BestWebSoft: from n/a through <= 1.5.2.

    Published: 23 Jan 2026
    4.3
    Medium

    CVE-2026-24596

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts-thumbnails allows Cross Site Request Forgery.This issue affects Related Posts Thumbnails Plugin for WordPress: from n/a through <= 4.3.2.

    Published: 23 Jan 2026
    5.4
    Medium

    CVE-2026-24595

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.9.

    Published: 23 Jan 2026