Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-66473 — WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-65448 — WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Site Scripting …

Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner &#8211; AcyChecker <= 1.8.1 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65447 — WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65446 — WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.5 MEDIUM
CVE-2026-65445 — WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulne…

Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions.

Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65443 — WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.2 HIGH
CVE-2026-65442 — WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65441 — WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65440 — WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65439 — WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS)…

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

ultimate_addons_for_contact_form_7 | Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65438 — WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Scripting (XSS…

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

message_filter_for_contact_form_7 | Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-65437 — WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - Cross Site Sc…

Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.1 HIGH
CVE-2026-61957 — WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting (XSS) vulner…

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
7.2 HIGH
CVE-2026-61953 — WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Forgery (SSRF)…

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

Remote | Server-Side Request Forgery
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2026-51565 — Milk Admin Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted …

| Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
0.0 NA
CVE-2025-63913 — OpenSBI Denial of Service Vulnerability

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU ex…

| Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-59240 — IDOR in Prospero Flow CRM allows deletion of other users' notifications

The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authentic…

prospero_flow_crm | Remote | Authorization
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
8.7 HIGH
CVE-2026-55685 — React Router: Unauthenticated Denial of Service via Inefficient Route Matching

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow do…

Remote | Denial of Service
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
5.1 MEDIUM
CVE-2026-53669 — React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypas…

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 an…

Remote | Misconfiguration
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
6.9 MEDIUM
CVE-2026-53668 — React Router: Open redirect can lead to XSS

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link …

Remote | Cross-Site Scripting
Jul 27, 2026 Jul 27, 2026
Jul 27, 2026
Jul 27, 2026
Showing 20 of 9336 Results