Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2026-18488 — Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'ta…

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 due to insuff…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.3 MEDIUM
CVE-2026-83744 — invoiceninja Invoice Ninja invoices Endpoint Purify.php isHostSafe server-side request fo…

A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the compo…

invoice_ninja | Remote | Server-Side Request Forgery
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-83743 — invoiceninja Invoice Ninja Vendor Portal Profile Update profile authorization

A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipul…

invoice_ninja | Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-82747 — Ash.Policy.Authorizer returns records denied by a runtime read policy to any actor

Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read policy (a check evaluated pe…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.9 MEDIUM
CVE-2026-77823 — LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter

The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. This is due to insufficient…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.9 MEDIUM
CVE-2026-76006 — Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Para…

The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 6.8.2 due to insufficient e…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-75965 — User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode Attribute in all …

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.2 HIGH
CVE-2026-75921 — Master Addons for Elementor <= 3.1.9 - Incorrect Authorization to Authenticated (Editor+)…

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrary File Upload in all versio…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-19952 — Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Pat…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and includi…

Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.3 MEDIUM
CVE-2026-19948 — Cozy Blocks <= 2.2.17 - Missing Authorization to Unauthenticated Unpublished Product Info…

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.…

Remote | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.8 HIGH
CVE-2026-19806 — Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administra…

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in a…

Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.2 HIGH
CVE-2026-19796 — Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthent…

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up to, and…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.2 HIGH
CVE-2026-19573 — Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via ‘do…

The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient …

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.5 MEDIUM
CVE-2026-18752 — Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wppl_device_id…

The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user suppl…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.9 MEDIUM
CVE-2026-17589 — Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL Injection v…

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escap…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-16787 — Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'd…

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, and including, 2.1.19 due…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-13203 — Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'c…

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section and dslc_modul…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.4 MEDIUM
CVE-2026-12747 — Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site …

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient inpu…

Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-82749 — Ash relationship parent(...) filter degrades to an IS NULL match when the parent field is…

Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field cannot be resolved. Loading a…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
2.1 LOW
CVE-2026-82748 — Ash.Actions.Aggregate authorizes an aggregate under one action but computes it under anot…

Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with policies that do not match the ac…

ash | Authorization
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 12178 Results