Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-97644 — Groundhogg <= 4.9 - Authenticated (Sales Person+) Privilege Escalation via Contact Identi…

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vul…

groundhogg | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-92977 — Real Cookie Banner: GDPR & ePrivacy Cookie Consent <= 5.3.5 - Unauthenticated Stored Cros…

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient in…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-92826 — EWWW Image Optimizer <= 8.7.7 - Reflected Cross-Site Scripting via REQUEST_URI Parameter …

The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 due to insufficient input sanit…

image_optimizer | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-92727 — EmbedPress <= 4.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slide…

The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slidesShow' Block A…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-92551 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppre…

profilepress | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-92538 — LearnPress <= 4.4.7 - Reflected DOM-Based Cross-Site Scripting via 'orderby' Parameter

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' parameter in all versions up …

learnpress | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
8.8 HIGH
CVE-2026-92536 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Res…

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all v…

profilepress | Remote | Information Disclosure
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.2 HIGH
CVE-2026-96270 — Ultimate Member <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'form_id' Par…

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' …

ultimate_member | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.5 MEDIUM
CVE-2026-95865 — Beaver Builder Page Builder <= 2.11.0.5 - Authenticated (Contributor+) SQL Injection via …

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all versions up to, and including, 2.11.0.…

beaver_builder | Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.5 MEDIUM
CVE-2026-94539 — SupportCandy <= 3.5.3 - Authenticated (Custom+) SQL Injection via 'sort_by' Parameter

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in all versions up to, and includi…

Remote | Injection
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.4 MEDIUM
CVE-2026-94378 — SupportCandy <= 3.5.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'name…

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and includi…

Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
7.5 HIGH
CVE-2026-93428 — Ultimate Member <= 2.13.1 - Missing Authorization to Unauthenticated Sensitive Profile Fi…

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, an…

ultimate_member | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.1 MEDIUM
CVE-2026-92243 — Ivory Search <= 5.5.18 - Reflected DOM-Based Cross-Site Scripting via 's' Parameter

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 5.5.18 due to insufficient …

ivory_search | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.4 MEDIUM
CVE-2026-100180 — Jeg Kit for Elementor <= 3.2.19 - Unauthenticated Stored Cross-Site Scripting via Comment

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and i…

jeg_elementor_kit | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.1 MEDIUM
CVE-2026-105090 — Formbricks Stored Cross-Site Scripting Vulnerability

Formbricks before 5.4.4 and 6 before 6.0.1 allows stored XSS. The survey-level Custom Head Scripts feature did not enforce the documented Manage permission boundary. A workspace member holding only r…

formbricks | Remote | Cross-Site Scripting
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
3.9 LOW
CVE-2026-105083 — ImageMagick before 7.1.2-32 and 6.9.13-57 Security Policy Bypass via policy.xml DOCTYPE

ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYP…

imagemagick | Misconfiguration
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.1 MEDIUM
CVE-2026-79113 — OpenAPV Heap-Based Buffer Overflow

OpenAPV before 1.1.1.0 has a read_bitstream heap-based buffer overflow.

| Memory Corruption
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
9.9 CRITICAL
CVE-2026-105080 — ConvertX Arbitrary Code Execution

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .download…

convertx | Remote | Misconfiguration
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
6.9 MEDIUM
CVE-2026-105030 — Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers lacking …

Remote | Information Disclosure
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
5.3 MEDIUM
CVE-2026-105029 — UVdesk support-center-bundle before 1.1.3.3 IDOR via rateTicket Ticket Rating Endpoint

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate ot…

community-skeleton | Remote | Authorization
Oct 03, 2026 Oct 03, 2026
Oct 03, 2026
Oct 03, 2026
Showing 20 of 14978 Results