CVE Vulnerability Database

Search and browse 377,995 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16547MEDIUM5.9The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en...
CVE-2026-16546MEDIUM4.3The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA...
CVE-2026-16536MEDIUM5.3The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef...
CVE-2026-16296MEDIUM4.7The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect...
CVE-2026-16295MEDIUM4.3The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p...
CVE-2026-16293MEDIUM6.8The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po...
CVE-2026-16070LOW2.7The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd...
CVE-2026-16069MEDIUM6.8The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t...
CVE-2026-16068LOW3.5The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does...
CVE-2026-16056MEDIUM4.3The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler...
CVE-2026-16035MEDIUM4.3The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP ...
CVE-2026-15958CRITICAL9.3The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its ...
CVE-2026-15233MEDIUM4.8The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at...
CVE-2026-14939MEDIUM6.8The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi...
CVE-2026-14872MEDIUM6.8The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e...
CVE-2026-14848MEDIUM5.4The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified th...
CVE-2026-14824MEDIUM4.8The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp...
CVE-2026-14816MEDIUM6.5The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th...
CVE-2026-12698MEDIUM4.3The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei...
CVE-2026-11366LOW3.7The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica...
CVE-2026-10526MEDIUM5.8The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th...
CVE-2026-68744LOW3.3A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for...
CVE-2026-18739LOW2.5A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when...
CVE-2026-18569LOW3.7A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui...
CVE-2026-16881HIGH8.7A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component...