Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-81770 — WordPress Interactive Geo Maps plugin <= 1.6.30 - Reflected Cross Site Scripting (XSS) vu…

Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-81769 — WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.8 CRITICAL
CVE-2026-81294 — WordPress Authorizer plugin <= 3.15.1 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-81289 — WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.13.1 - Cross …

Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-81288 — WordPress Upsell Order Bump Offer for WooCommerce plugin <= 3.1.5 - Cross Site Scripting …

Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.3 CRITICAL
CVE-2026-81286 — WordPress WCFM Marketplace plugin <= 3.8.1 - SQL Injection vulnerability

Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

wcfm_marketplace | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-81283 — WordPress WP User Frontend plugin <= 4.3.10 - PHP Object Injection vulnerability

Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.

wp_user_frontend | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-66652 — WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.

grand_tour | Remote | Cross-Site Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.6 HIGH
CVE-2026-82958 — Eclipse Ditto ImplicitThingCreationMessageMapper JSON Injection Vulnerability

In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id …

ditto | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.1 MEDIUM
CVE-2026-32773 — Apache Spark: XSS Vulnerability in Spark Web 3.5.4

There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead to a minimal privilege esc…

spark | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.1 HIGH
CVE-2026-19219 — DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certai…

telerik_ui_for_asp.net_ajax | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.5 HIGH
CVE-2026-18672 — RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik U…

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's i…

telerik_ui_for_asp.net_ajax | Remote | Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-84175 — Eclipse Ditto Server-Side Request Forgery Vulnerability

In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API users in the definition field of a Thing or Feature, without v…

ditto | Remote | Server-Side Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-53683 — Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No val…

enterprise_linux enterprise_linux | Remote | Server-Side Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.2 HIGH
CVE-2026-75528 — Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment A…

The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log in all versions up to, and including, 2.4.13 due to insufficient input sani…

broken_link_checker broken_link_checker | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-14828 — ManageEngine Password Manager Pro, PAM360, and Access Manager Plus SQL Injection Vulnerab…

Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerabil…

Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.4 MEDIUM
CVE-2025-7963 — Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting …

The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insuffici…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.1 HIGH
CVE-2026-82883 — WordPress Login With Ajax plugin <= 4.5.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a throug…

Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.4 MEDIUM
CVE-2026-3850 — Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact For…

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is …

divi divi | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.1 HIGH
CVE-2026-82183 — OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Unverified Ste…

The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its Steam single sign-on flow, allowing unauthenticated attackers to log in as an arbitrary …

oauth_single_sign_on | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12569 Results