Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

GitHub 🐙

Recent vulnerabilities · 379691 entries
ID Severity Description Published Updated
ghsa-vc58-2rcj-cgf8
7.5 (3.1)
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all ver… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-9949-jq7q-8g48
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly valida… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-82gv-pr29-8vm2
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCA… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-564m-jf3j-p556
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted b… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-3v9p-5xxf-6hxg
8.1 (3.1)
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in a… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-whfp-wchg-v9xw
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to m… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-r39q-9952-j46j
9.1 (3.1)
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversa… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-h8h9-7p7r-7rpq
8.8 (3.1)
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalati… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-h25v-5897-j3vf
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting be… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-fcq7-9xcx-6xxw
5.4 (3.1)
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Autho… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-f5pm-cq7v-xmjw
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its a… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-87mc-m7h4-wxp9
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-7hr3-mm9w-ghgw
6.1 (3.1)
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflec… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-7cq6-x444-93vj
7.2 (3.1)
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable t… 2026-10-02T06:30:55Z 2026-10-02T06:30:56Z
ghsa-3fm8-276x-m74x
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value b… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-2xw5-r48v-m7fg
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genu… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-24j4-6qf8-p4rw
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one … 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-xwfv-9j83-wfj7
9.8 (3.1)
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-x36m-2pwv-jrpp
7.2 (3.1)
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-m8mq-x2gc-8xcm
7.2 (3.1)
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and in… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-gcf4-jm96-42wg
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce prod… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-fwjj-2936-g23h
9.8 (3.1)
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up … 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-v78q-44mm-wf7q
7.3 (3.1)
5.5 (4.0)
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-r4mc-xrrj-f33f
6.3 (3.1)
2.1 (4.0)
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-qc9g-wj38-hfvp
7.5 (3.1)
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sen… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-mwfx-8rgq-rc8f
7.5 (3.1)
An API key is hardcoded and retrievable from the application package. Since Android applications ca… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-m6q3-w82g-46vw
7.3 (3.1)
5.5 (4.0)
A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. Affected by t… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-crm9-6p8f-6cx9
6.9 (4.0)
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attacke… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-4vh9-ff7c-v4f2
6.3 (3.1)
2.1 (4.0)
A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-48q5-8whv-r6xj
6.3 (3.1)
2.1 (4.0)
A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUs… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z