CVE Vulnerability Database

Search and browse 397,743 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8991MEDIUM4.4The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2026-8978MEDIUM4.9The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Inje...
CVE-2026-8502MEDIUM5.3The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive...
CVE-2026-7796MEDIUM6.4The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress i...
CVE-2026-7795MEDIUM6.4The Click to Chat – WA Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [chat] shortcode...
CVE-2026-7792MEDIUM5.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2026-7665MEDIUM5.3The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Informa...
CVE-2026-7566MEDIUM6.6The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...
CVE-2026-7565MEDIUM4.9The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Travers...
CVE-2026-7537HIGH7.2The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi...
CVE-2026-2500MEDIUM4.4The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. T...
CVE-2026-9281MEDIUM6.4The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress...
CVE-2026-9008MEDIUM4.3The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. Thi...
CVE-2026-8901HIGH7.2The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vuln...
CVE-2026-8438HIGH7.2The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2026-9719MEDIUM4.3The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Req...
CVE-2026-9290HIGH7.5The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in al...
CVE-2026-8976MEDIUM4.3The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is...
CVE-2026-8900MEDIUM6.4The Simple SEO Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in a...
CVE-2026-8893MEDIUM6.4The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribut...
CVE-2026-8608MEDIUM5.3The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verifi...
CVE-2026-7047MEDIUM4.3The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-6448MEDIUM4.9The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind SQL...
CVE-2026-6242MEDIUM6.8An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper han...
CVE-2026-6241MEDIUM6.8An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled ...