CVE Vulnerability Database

Search and browse 383,946 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14568MEDIUM6.5The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor...
CVE-2026-14289CRITICAL9The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request hand...
CVE-2026-14236MEDIUM4.7The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it...
CVE-2026-14235HIGH7.5The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session...
CVE-2026-14203MEDIUM4.8The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML...
CVE-2026-14190MEDIUM6.1The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input...
CVE-2026-14189LOW3.8The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them ...
CVE-2026-13726HIGH7.1The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons...
CVE-2026-13714CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded f...
CVE-2026-13597CRITICAL9.1The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check alwa...
CVE-2026-13400MEDIUM6.1Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl...
CVE-2026-13390MEDIUM5.3The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega...
CVE-2026-13332CRITICAL9.1The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX acti...
CVE-2026-13152HIGH8.1The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registrat...
CVE-2026-12982MEDIUM6.1The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it...
CVE-2026-12493HIGH7.5The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext...
CVE-2026-12394CRITICAL9.8The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing ...
CVE-2026-12255HIGH8.1The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques...
CVE-2026-10082MEDIUM6.1The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it...
CVE-2025-15662HIGH8.6The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl...
CVE-2026-15928HIGH8.2XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in...
CVE-2026-17501MEDIUM6.9A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file commo...
CVE-2026-17500MEDIUM6.9A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file...
CVE-2026-57990HIGH7.4Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t...
CVE-2026-57989HIGH7.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ...