Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-2917 — Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated …

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_duplicate_thing` admin action handler. T…

| Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-3903 — Modular Connector <= 2.5.1 - Cross-Site Request Forgery via postConfirmOauth

The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing nonc…

| Cross-Site Request Forgery
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-1708 — Appointment Booking Calendar <= 1.6.9.27 - Unauthenticated SQL Injection via 'append_wher…

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to blind SQL Injection in all versions up to, and including, 1.6.9.27. This is due to…

| Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-2918 — Happy Addons for Elementor <= 3.21.0 - Insecure Direct Object Reference to Authenticated …

The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.21.0 via the `ha_condition_update` AJAX action. This is d…

| Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-3826 — WellChoose|IFTOP - Local File Inclusion

IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

Remote | Path Traversal
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.1 MEDIUM
CVE-2026-3825 — WellChoose|IFTOP - Reflected Cross-site Scripting

Update to verison IFTOP_P4_181 or later.

Remote
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.1 MEDIUM
CVE-2026-3824 — WellChoose|IFTOP - Open redirect

IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

Remote | Misconfiguration
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.4 MEDIUM
CVE-2026-3534 — Astra <= 4.12.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta

The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-content-background-meta` post meta fields in all versions up to, and including, …

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.0 HIGH
CVE-2026-31844 — Authenticated SQL Injection in Koha displayby parameter of suggestion.pl

An authenticated SQL Injection vulnerability (CWE-89) in the displayby parameter of /cgi-bin/koha/suggestion/suggestion.pl in Koha allows a low-privileged staff user to execute arbitrary SQL queries …

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
2.7 LOW
CVE-2026-3911 — Org.keycloak.services.resources.admin.userresource: keycloak: information disclosure of d…

A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserResource component. By accessing a specific administrative endpoint, this user co…

Remote | Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.1 MEDIUM
CVE-2026-3884 — Spin.js Prototype Pollution Cross-site Scripting (XSS)

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker wo…

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
7.5 HIGH
CVE-2026-3222 — WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter

The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abst…

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.4 MEDIUM
CVE-2026-2707 — weForms <= 1.6.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Fi…

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint in all versions up to, and including, 1.6.27. This is due to inconsistent inpu…

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-2631 — Datalogics Ecommerce Delivery < 2.6.60 - Unauthenticated Privilege Escalation

The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. Th…

| Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-2626 — Divi Booster < 5.0.2 - Unauthenticated PHP Object Injection

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin…

| Authorization
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
0.0 NA
CVE-2026-2466 — DukaPress <= 3.2.4 - Reflected XSS

The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against hi…

| Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
6.4 MEDIUM
CVE-2026-2358 — WP ULike <= 5.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcod…

The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode `template` attribute in all versions up to, and including, 5.0.1. This is due …

Remote | Cross-Site Scripting
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-27842 — Cisco MR-GM Authentication Bypass Vulnerability

Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.

Remote | Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
9.8 CRITICAL
CVE-2026-24448 — "MR-GM5L-S1 and MR-GM5A-L1 Hard-Coded Credentials Vulnerability"

Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administrative access.

Remote | Authentication
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
7.2 HIGH
CVE-2026-20892 — "MR-GM5L-S1 and MR-GM5A-L1 Command Injection Vulnerability"

Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privileges to execute arbitrary commands.

Remote | Injection
Mar 11, 2026 Mar 11, 2026
Mar 11, 2026
Mar 11, 2026
Showing 20 of 5392 Results