CVE Vulnerability Database

Search and browse 381,202 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14834MEDIUM6.5The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX ...
CVE-2026-14833MEDIUM6.8The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend...
CVE-2026-14830HIGH7.5The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually...
CVE-2026-14554MEDIUM6.5The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them...
CVE-2026-14483CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver...
CVE-2026-14333HIGH7.5The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p...
CVE-2026-14319HIGH7.5The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri...
CVE-2026-14317MEDIUM5.3The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t...
CVE-2026-13609HIGH8.8The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af...
CVE-2026-13393LOW3.5The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item...
CVE-2026-13392HIGH7.2The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a...
CVE-2026-12721HIGH8.6The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us...
CVE-2026-12720HIGH7.5The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data ...
CVE-2026-12697MEDIUM5.4The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us...
CVE-2026-12695HIGH8.1The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted...
CVE-2026-12376MEDIUM4.3The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing...
CVE-2026-12251HIGH8.1The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m...
CVE-2026-63223CRITICAL9.8CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i...
CVE-2026-63222HIGH7.5CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us...
CVE-2026-63221CRITICAL9.4CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v...
CVE-2026-56673HIGH7.5ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path...
CVE-2026-56672HIGH8.2ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control...
CVE-2026-56671HIGH7.5ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ...
CVE-2026-56670HIGH8.2ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo...
CVE-2026-63220MEDIUM4.8CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For...