Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-7810 — UsamaK98 python-notebook-mcp server.py add_cell path traversal

A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. …

| Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-5159 — Royal Addons for Elementor <= 1.7.1056 - Authenticated (Contributor+) Stored Cross-Site S…

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up to, and including, …

| Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-4665 — WP Carousel Free <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-caption` attributes in all versions up to, and including, 2.7.10. This is due to the …

| Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-4803 — Royal Addons for Elementor <= 1.7.1056 - Unauthenticated Stored Cross-Site Scripting via …

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and inclu…

| Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-5957 — EmailKit <= 1.6.5 - Authenticated (Author+) Arbitrary File Read via 'emailkit-editor-temp…

The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This is due to a flawed path traversal validation in the create_template() method of …

| Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-2948 — Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (C…

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() fun…

| Server-Side Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-5294 — GeekyBot <= 1.2.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Installatio…

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispa…

| Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-3456 — GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.2.0 - Una…

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1…

| Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-35228 — Oracle Open Source Projects Oracle MCP Server Helper Tool SQL Injection Vulnerability

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulner…

| Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-6704 — Blog Settings <= 1.0 - Reflected Cross-Site Scripting via 'page' Parameter

The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0. This is due to insufficient input sanitizati…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-6702 — Publish 2 Ping.fm <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via …

The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the '/wp-admi…

Remote | Cross-Site Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.3 MEDIUM
CVE-2026-6701 — addfreespace <= 0.1.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting via Set…

The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.1.3. This is due to missing or incorrect nonce validation on a function. This…

Remote | Cross-Site Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.3 MEDIUM
CVE-2026-6700 — DX Sources <= 2.0.1 - Cross-Site Request Forgery to Settings Update

The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the settings_page_…

Remote | Cross-Site Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-6696 — Zingaya Click-to-Call <= 1.0 - Reflected Cross-Site Scripting via 'email' Parameter

The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_name', 'last_name', and 'phone' parameters on the plugin's sign-up admin page in…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-6255 — Simple Owl Shortcodes <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of the 'owls_wrapper' shortcode in all versions up to, and including, 2.1.1 due to …

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-5505 — WP-Clippy <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortco…

The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in all versions up to, and including, 1.0.0. This is due to insufficient input sani…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.5 MEDIUM
CVE-2026-5247 — Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, …

The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper' attribute of the [futureaction] shortcode in all versions up to,…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.5 HIGH
CVE-2026-5100 — AWP Classifieds <= 4.4.5 - Unauthenticated SQL Injection via 'regions'

The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versions up to, and including, 4.4.5 due to insufficient escaping on the user supplie…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.4 MEDIUM
CVE-2026-4730 — Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website <= 2.1…

The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'chartid' shortcode attribute in all v…

Remote | Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-4409 — Subscribe To Comments Reloaded <= 240119 - Improper Authorization to Unauthenticated Arbi…

The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up …

Remote | Authentication
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
Showing 20 of 5632 Results