CVE Vulnerability Database

Search and browse 394,301 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56051HIGH7.1Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
CVE-2026-56050MEDIUM6.5Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access ...
CVE-2026-56049HIGH8.5Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
CVE-2026-56042HIGH7.1Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
CVE-2026-56023MEDIUM5.4Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
CVE-2026-56014HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
CVE-2026-56013MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
CVE-2026-56006HIGH7.1Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
CVE-2026-56005HIGH7.1Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-54849CRITICAL9.3Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
CVE-2026-54848HIGH8.3Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R...
CVE-2026-54845HIGH8.1Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.
CVE-2026-54844HIGH7.5Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
CVE-2026-54843CRITICAL9.3Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
CVE-2026-54842HIGH8.1Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-54841HIGH7.5Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
CVE-2026-54838HIGH8.5Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
CVE-2026-54836CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ...
CVE-2026-54830HIGH7.5Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
CVE-2026-54829HIGH7.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt...
CVE-2026-54828HIGH7.5Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
CVE-2026-54823CRITICAL9.9Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-54822HIGH8.5Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
CVE-2026-54821HIGH7.4Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
CVE-2026-52690MEDIUM5.9Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D...