CVE Vulnerability Database

Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-3896MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj...
CVE-2026-3895MEDIUM6.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-3375HIGH7.2The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti...
CVE-2026-3279MEDIUM6.5The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-3001MEDIUM6.1The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version...
CVE-2026-2030MEDIUM6.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2025-41670HIGH8.7A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating co...
CVE-2025-41669HIGH8.8The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloade...
CVE-2026-9200HIGH7.5The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2...
CVE-2026-9014MEDIUM5.3The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2026-8994HIGH8.1The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0....
CVE-2026-8943MEDIUM4.3The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-8941MEDIUM4.3The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8939MEDIUM4.3The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2026-8938MEDIUM4.3The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-8911MEDIUM6.1The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2026-8903MEDIUM4.3The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al...
CVE-2026-8899MEDIUM6.4The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in a...
CVE-2026-8898MEDIUM6.4The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in v...
CVE-2026-8897MEDIUM6.4The Shortcode Buddy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all ve...
CVE-2026-8894MEDIUM6.4The iWR Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `iwrtooltip` shortcod...
CVE-2026-8891MEDIUM6.4The BitForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bitform' shortcode in ve...
CVE-2026-8887MEDIUM6.4The Listen Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'listen' shortcode in ver...
CVE-2026-8886MEDIUM6.4The hk_shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title-plane' shortcode in ve...
CVE-2026-8884MEDIUM6.4The Instant-Quote.co Quotation Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attr...