CVE Vulnerability Database

Search and browse 397,819 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-53346MEDIUM4.3Missing Authorization vulnerability in ThimPress Thim Core allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2025-53345HIGH8.8Missing Authorization vulnerability leading to code execution after installing malicious vulnerable plugin in ThimPress ...
CVE-2025-53302MEDIUM5.3Missing Authorization vulnerability in Anton Shevchuk Constructor allows Accessing Functionality Not Properly Constraine...
CVE-2025-53209CRITICAL9.8Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff...
CVE-2025-52766MEDIUM6.5Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access ...
CVE-2025-52759HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Acco...
CVE-2026-9730MEDIUM4.3The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2026-9723MEDIUM4.3The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-9722MEDIUM4.3The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2026-9599MEDIUM4.3The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2026-9234MEDIUM4.3The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inc...
CVE-2026-8885MEDIUM6.4The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callo...
CVE-2026-8422MEDIUM4.3The Remove meta boxes per user role plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2026-4081MEDIUM6.4The ZeM STL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [zemstl] shortcode in all versions...
CVE-2026-4080MEDIUM6.4The Easy Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_to_cart' shortcode in all v...
CVE-2026-4071MEDIUM4.3The BirdSeed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2....
CVE-2026-3620MEDIUM4.4The Word Replacer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'replacement' parameter in a...
CVE-2026-3514HIGH7.5In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of UR...
CVE-2026-2425MEDIUM6.1The hiWeb Migration Simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'new_domain' par...
CVE-2026-2382MEDIUM6.4The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of ...
CVE-2026-1784HIGH8.8The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found...
CVE-2026-1451MEDIUM6.1The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'a' parameter in versions up to...
CVE-2026-1450MEDIUM6.1The rognone plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mode' parameter in versions up...
CVE-2025-5085MEDIUM5.5The WP Nano AD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘blogrole_link’ parameter in al...
CVE-2026-8293HIGH7.5The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its ...