CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15395HIGH7.2The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-15160MEDIUM4.3The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl...
CVE-2026-15159MEDIUM4.3The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2026-11324MEDIUM6.1The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros...
CVE-2026-62387HIGH7.1The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default C...
CVE-2026-62386HIGH8.2The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query...
CVE-2026-62241CRITICAL9.3clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')...
CVE-2026-62238HIGH8.8OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint ...
CVE-2026-62237MEDIUM6.5Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and ...
CVE-2026-62236MEDIUM5.4grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASec...
CVE-2026-62235MEDIUM6.3Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that al...
CVE-2026-62234HIGH8.4Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.w...
CVE-2026-62233HIGH8.8grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints...
CVE-2026-62232CRITICAL9.1Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FAS...
CVE-2026-62231HIGH8.6The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created wit...
CVE-2026-62230HIGH8.7Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access t...
CVE-2026-62229HIGH8.8OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lowe...
CVE-2026-62228HIGH8.8OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca...
CVE-2026-62227HIGH7.7OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that ...
CVE-2026-62226HIGH8.5OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to...
CVE-2026-62225MEDIUM5.4OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows l...
CVE-2026-62224MEDIUM5.4OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mu...
CVE-2026-62223HIGH8.8OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows ...
CVE-2026-62222HIGH7.8OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plu...
CVE-2026-62221MEDIUM5.4OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature...