Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-66580 — WordPress Product Feed Manager plugin <= 7.12.0 - SQL Injection vulnerability

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66579 — WordPress JetElements For Elementor plugin <= 2.9.2.1 - Cross Site Scripting (XSS) vulner…

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66578 — WordPress PropertyHive plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66577 — WordPress JetSearch plugin <= 3.6.3 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66576 — WordPress JetBlocks For Elementor plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerabil…

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.3 MEDIUM
CVE-2026-66575 — WordPress King Addons for Elementor plugin <= 51.1.81 - Insecure Direct Object References…

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66574 — WordPress Element Pack Elementor Addons plugin <= 8.8.3 - Cross Site Scripting (XSS) vuln…

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66573 — WordPress JetTabs plugin <= 2.3.3.1 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-66572 — WordPress JetBlog plugin <= 2.4.10 - Cross Site Scripting (XSS) vulnerability

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.1 HIGH
CVE-2026-66571 — WordPress Asset CleanUp: Page Speed Booster plugin <= 1.4.0.5 - Cross Site Request Forger…

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

Remote | Cross-Site Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-62108 — WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-62104 — WordPress Migratico Lite plugin <= 2.6.8 - Remote Code Execution (RCE) vulnerability

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.8 CRITICAL
CVE-2026-62101 — WordPress EduAdmin Booking plugin <= 5.4.2 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.1 HIGH
CVE-2026-90986 — WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.21 - Cross Site Scripting…

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.

Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.1 MEDIUM
CVE-2026-92932 — MISP sachertortephp Xml::build() Operator Precedence Bypass Allows Unintended HTTPS SSRF …

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition …

Remote | Server-Side Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.9 MEDIUM
CVE-2026-92921 — admin3 through 3.0.0 Weak Password Hashing via Single-Round MD5

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords thro…

Remote | Cryptography
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
5.4 MEDIUM
CVE-2026-92920 — admin3 through 3.0.0 Session Not Invalidated When a User Account Is Disabled

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bea…

Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.1 HIGH
CVE-2026-92919 — admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use …

Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-92918 — admin3 through 3.0.0 Session Token Disclosure via Audit Log

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /l…

Remote | Information Disclosure
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-92904 — Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoc…

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller'…

satellite satellite | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14856 Results