Latest CVE Feed
-
6.4
MEDIUMCVE-2026-1573
The OMIGO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `omigo_donate_button` shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. ... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2026-1570
The Simple Bible Verse via Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `verse` shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2026-1082
The TITLE ANIMATOR plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page form handler in `inc/settings-page.php`. This makes it possible for... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Request Forgery
-
6.4
MEDIUMCVE-2026-0555
The Premmerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premmerce_wizard_actions' AJAX endpoint in all versions up to, and including, 1.3.20. This is due to missing capability checks and insufficient input sanitization and... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-15477
The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attributes in all versions up to, and including, 0.1.5 due to insufficient escaping on the user supplied parameters and lack of sufficient ... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-15476
The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bucketlister_do_admin_ajax() function in all versions up to, and including, 0.1.5. This makes it possible for authenticat... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2026-2078
A vulnerability was detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function addPermission/updatePermission/deletePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\Permissi... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2026-2077
A security vulnerability has been detected in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this issue is the function addRole/updateRole/deleteRole of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2026-2076
A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected by this vulnerability is the function addUser/updateUser/deleteUser of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\Use... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2026-2075
A security flaw has been discovered in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. Affected is the function saveRolePermission of the file dataset\repos\warehouse\src\main\java\com\yeqifu\sys\controller\RoleController.java of the comp... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Authorization
-
0.0
NACVE-2025-15491
The Post Slides WordPress plugin through 1.0.1 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as with contributor or higher roles to perform LFI attacks... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Path Traversal
-
6.4
MEDIUMCVE-2025-15267
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.5.7 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-13463
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid component in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-12803
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bt_bb_tabs' shortcode in all versions up to, and including, 5.5.1 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-12159
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_raw_content shortcode in all versions up to, and including, 5.4.8 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2026-2074
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to ... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: XML External Entity
-
7.5
HIGHCVE-2026-2073
A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from rem... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Injection
-
6.8
MEDIUMCVE-2025-31990
Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unrespon... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Denial of Service
-
9.0
HIGHCVE-2026-2071
A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipulation of the argument except results in buffer overflow. The attack is possible to be carried ou... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Memory Corruption
-
6.2
MEDIUMCVE-2020-37171
TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an... Read more
Affected Products :- Published: Feb. 07, 2026
- Modified: Feb. 07, 2026
- Vuln Type: Denial of Service