Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-15896 — Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtf…

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possib…

Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
5.4 MEDIUM
CVE-2026-78471 — Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author …

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and out…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-92174 — SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion v…

The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'theme' parameter parameter. This makes it possible for a…

siteorigin_widgets_bundle | Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-90438 — Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (R…

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and i…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.8 HIGH
CVE-2026-15897 — Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege…

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's befor…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
8.1 HIGH
CVE-2026-92820 — Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts…

ninja_forms_file_uploads | Remote | Path Traversal
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.1 MEDIUM
CVE-2026-84925 — Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scri…

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions up to, and including, 7.16.1 due t…

avada | Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-19660 — Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Param…

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accep…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-10026 — CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution

The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 7.6.12. This is due to insufficient input validation on the 'Feed Config' field which is pa…

Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.2 HIGH
CVE-2026-93367 — Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Sc…

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title paramete…

Remote | Cross-Site Scripting
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.8 CRITICAL
CVE-2026-14378 — DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Take…

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` han…

Remote | Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-104123 — SourceCodester Online Reviewer Management System btn_functions.php activity sql injection

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /reviewer_0/admins/assessments/activities/…

online_reviewer_management_system | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-104120 — modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_ur…

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py…

mcp-server-everything mcp-server-fetch | Remote | Server-Side Request Forgery
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.9 MEDIUM
CVE-2026-21140 — ManagedProvisioning Improper Access Control Vulnerability

Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.

| Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
9.4 CRITICAL
CVE-2026-104480 — Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membe…

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice …

| Authentication
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104054 — calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking auth…

A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC Permission Engine.…

cal.diy | Remote | Authorization
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104053 — itsourcecode Pet Shop Management System admin_reservefilter.php sql injection

A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filte…

pet_shop_management_system | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
6.5 MEDIUM
CVE-2026-104052 — itsourcecode Pet Shop Management System admin_reject_completed.php sql injection

A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID…

pet_shop_management_system | Remote | Injection
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-103098 — GV-Eye Sensitive information exposure in URL query parameter Vulnerability

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An at…

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
7.5 HIGH
CVE-2026-103097 — GV-Eye Relay Payment API Key Vulnerability

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may …

Remote | Information Disclosure
Oct 02, 2026 Oct 02, 2026
Oct 02, 2026
Oct 02, 2026
Showing 20 of 14875 Results