Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25386

Missing Authorization vulnerability in Elementor Ally pojo-accessibility allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ally: from n/a through <= 4.0.2.

PUBLISHED
Vendor
Elementor
Product
Ally
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25385

Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3.

PUBLISHED
Vendor
KaizenCoders
Product
URL Shortify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25384

Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.8.5.

PUBLISHED
Vendor
WP Lab
Product
WP-Lister Lite for eBay
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25383

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through <= 3.6.16.

PUBLISHED
Vendor
Iqonic Design
Product
KiviCare
Provider severity
HIGH
Conflicts
0

CVE-2026-25382

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes IdealAuto idealauto allows PHP Local File Inclusion.This issue affects IdealAuto: from n/a through < 3.8.6.

PUBLISHED
Vendor
jwsthemes
Product
IdealAuto
Provider severity
HIGH
Conflicts
0

CVE-2026-25381

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects LoveDate: from n/a through < 3.8.6.

PUBLISHED
Vendor
jwsthemes
Product
LoveDate
Provider severity
HIGH
Conflicts
0

CVE-2026-25380

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Feedy feedy allows PHP Local File Inclusion.This issue affects Feedy: from n/a through < 2.1.5.

PUBLISHED
Vendor
jwsthemes
Product
Feedy
Provider severity
HIGH
Conflicts
0

CVE-2026-2538

A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolled search path. Attacking locally is a requirement. The attack's complexity is rated as high. The exploitability is told to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Flos Freeware
Product
Notepad2
Provider severity
HIGH
Conflicts
2

CVE-2026-25379

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes StreamVid streamvid allows PHP Local File Inclusion.This issue affects StreamVid: from n/a through < 6.8.6.

PUBLISHED
Vendor
jwsthemes
Product
StreamVid
Provider severity
HIGH
Conflicts
0

CVE-2026-25378

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Blind SQL Injection.This issue affects Nelio AB Testing: from n/a through <= 8.2.4.

PUBLISHED
Vendor
Nelio Software
Product
Nelio AB Testing
Provider severity
HIGH
Conflicts
0

CVE-2026-25377

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

PUBLISHED
Vendor
eyecix
Product
Addon Jobsearch Chat
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25376

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows Reflected XSS.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0.

PUBLISHED
Vendor
eyecix
Product
Addon Jobsearch Chat
Provider severity
HIGH
Conflicts
0

CVE-2026-25375

Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.10.

PUBLISHED
Vendor
WP Chill
Product
Image Photo Gallery Final Tiles Grid
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25374

Missing Authorization vulnerability in raratheme Spa and Salon spa-and-salon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spa and Salon: from n/a through <= 1.3.2.

PUBLISHED
Vendor
raratheme
Product
Spa and Salon
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25373

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/a through < 6.8.

PUBLISHED
Vendor
ProgressionStudios
Product
Vayvo
Provider severity
HIGH
Conflicts
0

CVE-2026-25372

Missing Authorization vulnerability in Kodezen LLC Academy LMS academy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Academy LMS: from n/a through <= 3.5.3.

PUBLISHED
Vendor
Kodezen LLC
Product
Academy LMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25371

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9.

PUBLISHED
Vendor
King-Theme
Product
Lumise Product Designer
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25370

Missing Authorization vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Compress: from n/a through <= 6.60.28.

PUBLISHED
Vendor
AresIT
Product
WP Compress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2537

A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component HTTP POST Request Handler. Such manipulation of the argument timestr leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Comfast
Product
CF-E4
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25369

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through <= 3.15.9.

PUBLISHED
Vendor
flexmls
Product
Flexmls® IDX
Provider severity
HIGH
Conflicts
0

CVE-2026-25368

Missing Authorization vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculated Fields Form: from n/a through <= 5.4.4.1.

PUBLISHED
Vendor
codepeople
Product
Calculated Fields Form
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25367

Missing Authorization vulnerability in NooTheme CitiLights noo-citilights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CitiLights: from n/a through < 3.7.2.

PUBLISHED
Vendor
NooTheme
Product
CitiLights
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25366

Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.

PUBLISHED
Vendor
Themeisle
Product
Woody ad snippets
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25365

Missing Authorization vulnerability in Özgür KARALAR Kargo Takip kargo-takip-turkiye allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kargo Takip: from n/a through < 0.2.4.

PUBLISHED
Vendor
Özgür KARALAR
Product
Kargo Takip
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25364

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.

PUBLISHED
Vendor
BoldGrid
Product
Client Invoicing by Sprout Invoices
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25363

Missing Authorization vulnerability in FooPlugins FooGallery foogallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FooGallery: from n/a through <= 3.1.11.

PUBLISHED
Vendor
FooPlugins
Product
FooGallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25362

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FooPlugins FooGallery foogallery allows Stored XSS.This issue affects FooGallery: from n/a through <= 3.1.11.

PUBLISHED
Vendor
FooPlugins
Product
FooGallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25361

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through <= 5.1.4.

PUBLISHED
Vendor
magepeopleteam
Product
WpEvently
Provider severity
HIGH
Conflicts
0

CVE-2026-25360

Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection.This issue affects Vex: from n/a through < 1.2.9.

PUBLISHED
Vendor
rascals
Product
Vex
Provider severity
HIGH
Conflicts
0

CVE-2026-2536

A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admin_AttrFlow.java of the component Workflow Engine. This manipulation of the argument File causes xml external entity reference. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Vendor
opencc
Product
JFlow
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25359

Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection.This issue affects Pendulum: from n/a through < 3.1.5.

PUBLISHED
Vendor
rascals
Product
Pendulum
Provider severity
HIGH
Conflicts
0

CVE-2026-25358

Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection.This issue affects Meloo: from n/a through < 2.8.2.

PUBLISHED
Vendor
rascals
Product
Meloo
Provider severity
HIGH
Conflicts
0

CVE-2026-25357

Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7.

PUBLISHED
Vendor
azzaroco
Product
Ultimate Membership Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-25356

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Yobazar yobazar allows Reflected XSS.This issue affects Yobazar: from n/a through < 1.6.7.

PUBLISHED
Vendor
skygroup
Product
Yobazar
Provider severity
HIGH
Conflicts
0

CVE-2026-25355

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Sanzo sanzo allows Stored XSS.This issue affects Sanzo: from n/a through < 2.4.3.

PUBLISHED
Vendor
skygroup
Product
Sanzo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25354

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Reebox reebox allows Reflected XSS.This issue affects Reebox: from n/a through < 1.4.8.

PUBLISHED
Vendor
skygroup
Product
Reebox
Provider severity
HIGH
Conflicts
0

CVE-2026-25353

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Nooni nooni allows Reflected XSS.This issue affects Nooni: from n/a through < 1.5.1.

PUBLISHED
Vendor
skygroup
Product
Nooni
Provider severity
HIGH
Conflicts
0

CVE-2026-25352

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyDecor mydecor allows Reflected XSS.This issue affects MyDecor: from n/a through < 1.5.9.

PUBLISHED
Vendor
skygroup
Product
MyDecor
Provider severity
HIGH
Conflicts
0

CVE-2026-25351

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup MyMedi mymedi allows Reflected XSS.This issue affects MyMedi: from n/a through < 1.7.7.

PUBLISHED
Vendor
skygroup
Product
MyMedi
Provider severity
HIGH
Conflicts
0

CVE-2026-25350

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Miti miti allows Reflected XSS.This issue affects Miti: from n/a through < 1.5.3.

PUBLISHED
Vendor
skygroup
Product
Miti
Provider severity
HIGH
Conflicts
0

CVE-2026-2535

A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argument channel results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Comfast
Product
CF-N1 V2
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25349

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Loobek loobek allows Reflected XSS.This issue affects Loobek: from n/a through < 1.5.2.

PUBLISHED
Vendor
skygroup
Product
Loobek
Provider severity
HIGH
Conflicts
0

CVE-2026-25348

Missing Authorization vulnerability in alttextai Download Alt Text AI alttext-ai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Alt Text AI: from n/a through <= 1.10.15.

PUBLISHED
Vendor
alttextai
Product
Download Alt Text AI
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25347

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acato WP REST Cache wp-rest-cache allows Stored XSS.This issue affects WP REST Cache: from n/a through <= 2026.1.0.

PUBLISHED
Vendor
Acato
Product
WP REST Cache
Provider severity
HIGH
Conflicts
0

CVE-2026-25346

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro FAQ Builder AYS faq-builder-ays allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FAQ Builder AYS: from n/a through <= 1.8.2.

PUBLISHED
Vendor
Ays Pro
Product
FAQ Builder AYS
Provider severity
HIGH
Conflicts
0

CVE-2026-25345

Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects SimpLy Gallery: from n/a through <= 3.3.2.

PUBLISHED
Vendor
GalleryCreator
Product
SimpLy Gallery
Provider severity
CRITICAL
Conflicts
0

CVE-2026-25344

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review Schema: from n/a through <= 2.2.6.

PUBLISHED
Vendor
RadiusTheme
Product
Review Schema
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25343

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS wp-sms allows DOM-Based XSS.This issue affects WP SMS: from n/a through <= 7.1.

PUBLISHED
Vendor
VeronaLabs
Product
WP SMS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25342

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kutethemes Boutique kute-boutique allows Reflected XSS.This issue affects Boutique: from n/a through < 2.4.6.

PUBLISHED
Vendor
kutethemes
Product
Boutique
Provider severity
HIGH
Conflicts
0

CVE-2026-25341

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a through <= 1.1.45.

PUBLISHED
Vendor
RSJoomla!
Product
RSFirewall!
Provider severity
HIGH
Conflicts
0