Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-7651 — User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Obj…

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure…

user_registration_\&_membership | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
7.2 HIGH
CVE-2026-7634 — SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting via User-Agent…

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitizatio…

slimstat_analytics | Remote | Cross-Site Scripting
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
4.3 MEDIUM
CVE-2026-7621 — SMTP2GO for WordPress <= 1.16.0 - Missing Authorization to Authenticated (Subscriber+) Lo…

The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.16.0. This is due to the plugin not properly verifying th…

smtp2go | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
5.3 MEDIUM
CVE-2026-7552 — Geo Mashup <= 1.13.19 - Missing Authorization to Unauthenticated Plugin Settings Disclosu…

The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to …

geo_mashup | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
7.2 HIGH
CVE-2026-7052 — HT Contact Form <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting via File Upload Fi…

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.…

May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.1 HIGH
CVE-2026-6455 — WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary File Deleti…

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and i…

Remote | Cross-Site Request Forgery
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
6.4 MEDIUM
CVE-2026-6427 — a3 Lazy Load <= 2.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Vide…

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HT…

Remote | Cross-Site Scripting
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
7.0 HIGH
CVE-2026-44604 — Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directo…

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts t…

May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
5.3 MEDIUM
CVE-2026-9803 — Keycloak: keycloak: denial of service via malformed authorization header

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authori…

build_of_keycloak | Remote | Denial of Service
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
6.8 MEDIUM
CVE-2026-9802 — Keycloak: keycloak: unauthorized account access via replayed refresh tokens after cluster…

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, w…

build_of_keycloak | Remote | Authentication
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
4.9 MEDIUM
CVE-2026-9801 — Keycloak: keycloak: denial of service via malformed ldap password policy response

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromi…

build_of_keycloak | Remote | Denial of Service
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-9798 — Keycloak: keycloak: brute-force protection bypass in ciba flow

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client cr…

build_of_keycloak | Remote | Authentication
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
6.8 MEDIUM
CVE-2026-9673 — Json-2-Csv CSV Injection

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV fil…

| Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.4 MEDIUM
CVE-2026-9644 — LiveSmart Video Chat <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due …

Remote | Cross-Site Scripting
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.8 HIGH
CVE-2026-9009 — Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author+) Remote Co…

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due t…

Remote | Injection
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
4.3 MEDIUM
CVE-2026-7533 — Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking…

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth…

easy_digital_downloads | Remote | Cross-Site Request Forgery
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-3173 — Meta Field Block <= 1.5.1 - Insecure Direct Object Reference to Authenticated (Contributo…

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary …

Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-9796 — Keycloak: keycloak: privilege escalation via time-of-check to time-of-use (toctou) vulner…

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This…

build_of_keycloak | Remote | Race Condition
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
7.3 HIGH
CVE-2026-9795 — Keycloak: keycloak: privilege escalation via improper scope mapping enforcement

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, in…

build_of_keycloak | Remote | Authorization
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-9794 — Keycloak: keycloak: information disclosure via saml ecp endpoint

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced…

build_of_keycloak | Remote | Information Disclosure
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
Showing 20 of 7198 Results