Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-2219 — Debian dpkg-denial of Service (DoS) Vulnerability

It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate the end of the data stream when uncompressing a zstd-compressed .deb archive, wh…

dpkg | Denial of Service
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
0.0 NA
CVE-2026-24308 — Apache ZooKeeper: Sensitive information disclosure in client configuration handling

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the cli…

zookeeper | Information Disclosure
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
0.0 NA
CVE-2026-24281 — Apache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper …

Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper ser…

zookeeper | Authentication
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.1 MEDIUM
CVE-2026-2433 — RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.11 - Unaut…

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via postMessage in all versions up to, and including, …

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.4 MEDIUM
CVE-2026-2420 — LotekMedia Popup Form <= 1.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripti…

The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.6 due to insufficient input sanitization …

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1825 — Show YouTube video <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitizat…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1824 — Infomaniak Connect for OpenID <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site S…

The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_login' parameter of the infomaniak_connect_generic_auth_url shortcode in all vers…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1823 — Consensus Embed <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sr…

The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortcode in all versions up to, and including, 1.6 due to insufficient input sanitiza…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1820 — Media Library Alt Text Editor <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site S…

The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bvmalt_sc_div_update_alt_text' shortcode in all versions up to, and including, 1.…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1805 — DA Media GigList <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist shortcode in all versions up to, and including, 1.9.0 due to insufficient input…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1574 — MyQtip – easy qTip2 <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shortcode in all versions up to, and including, 2.0.5 due to insufficient input san…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
6.4 MEDIUM
CVE-2026-1569 — Wueen <= 0.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Sh…

The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode in all versions up to, and including, 0.2.0 due to insufficient input sanitizati…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.3 MEDIUM
CVE-2026-1087 — The Guardian News Feed <= 1.2 - Cross-Site Request Forgery to Settings Update

The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing nonce validation on the settings update funct…

Remote | Cross-Site Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.3 MEDIUM
CVE-2026-1086 — Font Pairing Preview For Landing Pages <= 1.3 - Cross-Site Request Forgery to Settings Up…

The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the s…

Remote | Cross-Site Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.3 MEDIUM
CVE-2026-1085 — True Ranker <= 2.2.9 - Cross-Site Request Forgery to Unauthorized True Ranker Disconnecti…

The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.9. This is due to missing nonce validation on the seolocalrank-signout actio…

Remote | Cross-Site Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
7.2 HIGH
CVE-2026-1074 — WP App Bar <= 1.5 - Unauthenticated Stored Cross-Site Scripting via 'app-bar-features' Pa…

The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in all versions up to, and including, 1.5. This is due to insufficient input sani…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.3 MEDIUM
CVE-2026-1073 — Purchase Button For Affiliate Link <= 1.0.2 - Cross-Site Request Forgery to Settings Upda…

The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This is due to missing nonce validation on the set…

Remote | Cross-Site Request Forgery
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.4 MEDIUM
CVE-2026-1071 — Carta Online <= 2.13.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via P…

The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output es…

Remote | Cross-Site Scripting
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
7.2 HIGH
CVE-2025-14675 — Meta Box <= 5.11.1 - Authenticated (Contributor+) Arbitrary File Deletion

The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_delete_file' function in all versions up to, and including, 5.11.1. Th…

Remote | Path Traversal
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
4.3 MEDIUM
CVE-2026-30842 — Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avat…

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user to delete avatar files uploaded by other users. The avatar deletion …

wallos | Remote | Authorization
Mar 07, 2026 Mar 07, 2026
Mar 07, 2026
Mar 07, 2026
Showing 20 of 5128 Results