Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-57416

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.

PUBLISHED
Vendor
SiteGround
Product
SiteGround Email Marketing
Provider severity
HIGH
Conflicts
0

CVE-2026-57415

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.

PUBLISHED
Vendor
Codemenschen
Product
Gift Vouchers
Provider severity
HIGH
Conflicts
0

CVE-2026-57414

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.

PUBLISHED
Vendor
QuantumCloud
Product
ChatBot for eCommerce &#8211; WoowBot
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57413

Server-Side Request Forgery (SSRF) vulnerability in bdthemes Instant Image Generator ai-image allows Server Side Request Forgery.This issue affects Instant Image Generator: from n/a through <= 2.1.4.

PUBLISHED
Vendor
bdthemes
Product
Instant Image Generator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57412

Missing Authorization vulnerability in Codemenschen Gift Vouchers gift-voucher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gift Vouchers: from n/a through <= 4.6.9.

PUBLISHED
Vendor
Codemenschen
Product
Gift Vouchers
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57411

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views &#8211; Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2.

PUBLISHED
Vendor
Aman
Product
CF7 Views &#8211; Complete Entry Management for Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-57410

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.

PUBLISHED
Vendor
MailerPress Team
Product
MailerPress
Provider severity
HIGH
Conflicts
0

CVE-2026-5741

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
suvarchal
Product
docker-mcp-server
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-57409

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0.

PUBLISHED
Vendor
RealMag777
Product
Active Products Tables for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-57408

Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2.

PUBLISHED
Vendor
peachpayments
Product
Peach Payments Gateway
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57407

Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.

PUBLISHED
Vendor
WP Swings
Product
PDF Generator for WordPress
Provider severity
HIGH
Conflicts
0

CVE-2026-57406

Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6.

PUBLISHED
Vendor
Roxnor
Product
FundEngine
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57405

Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.

PUBLISHED
Vendor
themehunk
Product
Open Shop
Provider severity
HIGH
Conflicts
0

CVE-2026-57404

Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.

PUBLISHED
Vendor
magepeopleteam
Product
Booking and Rental Manager
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57403

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.

PUBLISHED
Vendor
Milan Petrovic
Product
GD Security Headers
Provider severity
HIGH
Conflicts
0

CVE-2026-57402

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdesk Flexible Refund and Return Order for WooCommerce flexible-refund-and-return-order-for-woocommerce allows Stored XSS.This issue affects Flexible Refund and Return Order for WooCommerce: from n/a through <= 1.0.51.

PUBLISHED
Vendor
wpdesk
Product
Flexible Refund and Return Order for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57401

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.

PUBLISHED
Vendor
Brainstorm Force
Product
SureDash
Provider severity
CRITICAL
Conflicts
0

CVE-2026-57400

Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.

PUBLISHED
Vendor
WP Swings
Product
Event Tickets Manager for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5740

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage for all users via a crafted binary WebSocket message sent to the public WebSocket endpoint.. Mattermost Advisory ID: MMSA-2026-00647

PUBLISHED
Vendor
Mattermost
Product
Mattermost
Provider severity
HIGH
Conflicts
0

CVE-2026-57399

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.

PUBLISHED
Vendor
Proxy &amp; VPN Blocker
Product
Proxy &amp; VPN Blocker
Provider severity
HIGH
Conflicts
0

CVE-2026-57398

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3.

PUBLISHED
Vendor
WebCodingPlace
Product
Real Estate Manager Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-57397

Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

PUBLISHED
Vendor
ThimPress.
Product
Coaching
Provider severity
HIGH
Conflicts
0

CVE-2026-57396

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0.

PUBLISHED
Vendor
Flintop
Product
Free Gifts for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-57395

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

PUBLISHED
Vendor
Themefic
Product
Tourfic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57394

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

PUBLISHED
Vendor
Tribulant Software
Product
Newsletters
Provider severity
HIGH
Conflicts
0

CVE-2026-57393

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.

PUBLISHED
Vendor
EDGARROJAS
Product
WooCommerce PDF Invoice Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57392

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

PUBLISHED
Vendor
Themefic
Product
Tourfic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57391

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Stored XSS.This issue affects Loops & Logic: from n/a through <= 4.2.3.

PUBLISHED
Vendor
Tangible
Product
Loops & Logic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57390

Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.

PUBLISHED
Vendor
EDGARROJAS
Product
Extra Product Options Builder for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-5739

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nodeParams results in code injection. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
n/a
Product
PowerJob
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-57389

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.

PUBLISHED
Vendor
Adrian Tobey
Product
Groundhogg
Provider severity
HIGH
Conflicts
0

CVE-2026-57388

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.

PUBLISHED
Vendor
Themefic
Product
Hydra Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-57387

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through <= 3.5.1.

PUBLISHED
Vendor
picu
Product
picu
Provider severity
HIGH
Conflicts
0

CVE-2026-57386

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

PUBLISHED
Vendor
Kodezen LLC
Product
aBlocks
Provider severity
HIGH
Conflicts
0

CVE-2026-57385

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2.

PUBLISHED
Vendor
appsbd
Product
Vitepos
Provider severity
HIGH
Conflicts
0

CVE-2026-57384

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

PUBLISHED
Vendor
Membership Software
Product
WishList Member X
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57383

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

PUBLISHED
Vendor
eyecix
Product
JobSearch
Provider severity
HIGH
Conflicts
0

CVE-2026-57382

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.

PUBLISHED
Vendor
Mitchell Bennis
Product
Simple File List
Provider severity
HIGH
Conflicts
0

CVE-2026-57381

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.

PUBLISHED
Vendor
Property Hive
Product
PropertyHive
Provider severity
HIGH
Conflicts
0

CVE-2026-57380

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1.

PUBLISHED
Vendor
hupe13
Product
Extensions for Leaflet Map
Provider severity
HIGH
Conflicts
0

CVE-2026-57379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

PUBLISHED
Vendor
WPPOOL
Product
FormyChat
Provider severity
HIGH
Conflicts
0

CVE-2026-57378

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.

PUBLISHED
Vendor
Phil Kurth
Product
Advanced Forms
Provider severity
HIGH
Conflicts
0

CVE-2026-57377

Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowAddons: from n/a through <= 1.6.8.

PUBLISHED
Vendor
WPXPO
Product
WowAddons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57376

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.

PUBLISHED
Vendor
Element Invader
Product
ElementInvader Addons for Elementor
Provider severity
HIGH
Conflicts
0

CVE-2026-57375

Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4.

PUBLISHED
Vendor
FluxBuilder
Product
MStore API
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57374

Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

PUBLISHED
Vendor
Wisetr INC.
Product
Funnel Kit Funnel Builder PRO
Provider severity
HIGH
Conflicts
0

CVE-2026-57373

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

PUBLISHED
Vendor
Wisetr INC.
Product
Funnel Kit Funnel Builder PRO
Provider severity
MEDIUM
Conflicts
0

CVE-2026-57372

Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.

PUBLISHED
Vendor
denishua
Product
WPJAM Basic
Provider severity
HIGH
Conflicts
0

CVE-2026-57371

Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a through <= 7.0.

PUBLISHED
Vendor
denishua
Product
WPJAM Basic
Provider severity
HIGH
Conflicts
0

CVE-2026-57370

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

PUBLISHED
Vendor
CODEPRESS IT Solutions LLC
Product
Visitor Traffic Real Time Statistics Pro
Provider severity
HIGH
Conflicts
0