CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2026-57695

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57693

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spacetime Ad Inserter ad-inserter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ad Inserter: from n/a through <= 2.8.11.

    Published: 13 Jul 2026
    5.8
    Medium

    CVE-2026-57691

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware Security and Brute-Force Firewall gotmls allows Reflected XSS.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through <= 4.23.89.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57668

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57694

    Last Modified: 13 Jul 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57424

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57423

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57422

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57421

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57420

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57418

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57417

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Cart Lift cart-lift allows Stored XSS.This issue affects Cart Lift: from n/a through <= 3.1.57.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57419

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 3.1.8.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57416

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57415

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57414

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.

    Published: 13 Jul 2026
    6.4
    Medium

    CVE-2026-57413

    Last Modified: 13 Jul 2026

    Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57412

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Vouchers: from n/a through <= 4.6.9.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57411

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views &#8211; Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2.

    Published: 13 Jul 2026
    8.8
    High

    CVE-2026-57410

    Last Modified: 13 Jul 2026

    Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57409

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57408

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57406

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.

    Published: 13 Jul 2026
    7.2
    High

    CVE-2026-57407

    Last Modified: 13 Jul 2026

    Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57404

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57405

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57403

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57402

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <= 1.0.51.

    Published: 13 Jul 2026
    9.9
    Critical

    CVE-2026-57401

    Last Modified: 13 Jul 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57400

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57398

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57399

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57395

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57396

    Last Modified: 27 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57393

    Last Modified: 21 Jul 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57394

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57392

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57391

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Stored XSS.This issue affects Loops & Logic: from n/a through <= 4.2.3.

    Published: 13 Jul 2026
    6.5
    Medium

    CVE-2026-57390

    Last Modified: 14 Jul 2026

    Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.

    Published: 13 Jul 2026
    8.6
    High

    CVE-2026-57389

    Last Modified: 13 Jul 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57388

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57387

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through <= 3.5.1.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57383

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57382

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.

    Published: 13 Jul 2026
    8.5
    High

    CVE-2026-57385

    Last Modified: 13 Jul 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2.

    Published: 13 Jul 2026
    8.8
    High

    CVE-2026-57386

    Last Modified: 13 Jul 2026

    Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57381

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57379

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

    Published: 13 Jul 2026
    7.1
    High

    CVE-2026-57380

    Last Modified: 13 Jul 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1.

    Published: 13 Jul 2026
    7.5
    High

    CVE-2026-57378

    Last Modified: 13 Jul 2026

    Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.

    Published: 13 Jul 2026