CVE Vulnerability Database
Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3896 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj... |
| CVE-2026-3895 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `... |
| CVE-2026-3375 | HIGH | 7.2 | 0.4% | May 27, 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti... |
| CVE-2026-3279 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-3001 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version... |
| CVE-2026-2030 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `... |
| CVE-2025-41670 | HIGH | 8.7 | 0.2% | May 27, 2026 | A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating co... |
| CVE-2025-41669 | HIGH | 8.8 | 0.2% | May 27, 2026 | The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloade... |
| CVE-2026-9200 | HIGH | 7.5 | 0.5% | May 27, 2026 | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2... |
| CVE-2026-9014 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2026-8994 | HIGH | 8.1 | 0.4% | May 27, 2026 | The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.... |
| CVE-2026-8943 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-8941 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2026-8939 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2026-8938 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-8911 | MEDIUM | 6.1 | 0.1% | May 27, 2026 | The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2026-8903 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al... |
| CVE-2026-8899 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in a... |
| CVE-2026-8898 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in v... |
| CVE-2026-8897 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve... |
| CVE-2026-8894 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcod... |
| CVE-2026-8891 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in ve... |
| CVE-2026-8887 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in ver... |
| CVE-2026-8886 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in ve... |
| CVE-2026-8884 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attr... |
