Vulnerabilities
Recent vulnerabilities
Recent vulnerabilities from
Select from 81 available sources using the dropdown above.
| ID | CVSS | Description | Vendor | Product | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-18036 |
8.2 (4.0)
|
NTRU leaks private key information by reducing secret … |
Legion of the Bouncy Castle Inc. |
BC-JAVA |
2026-10-02T07:54:16.063Z | 2026-10-02T07:54:16.063Z |
| CVE-2026-97637 |
9.8 (3.1)
|
JSON API Auth <= 3.1.2 - Unauthenticated Authenticatio… |
parorrey |
JSON API Auth |
2026-10-02T07:39:29.363Z | 2026-10-02T07:39:29.363Z |
| CVE-2026-94432 |
5.3 (3.1)
|
Appointment Booking Plugin <= 5.7.1 - Insecure Direct … |
latepoint |
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress |
2026-10-02T07:39:29.009Z | 2026-10-02T07:39:29.009Z |
| CVE-2026-97338 |
6.4 (3.1)
|
Download Manager <= 3.3.70 - Authenticated (Subscriber… |
codename065 |
Download Manager |
2026-10-02T07:39:28.690Z | 2026-10-02T07:39:28.690Z |
| CVE-2026-97634 |
6.5 (3.1)
|
Event Tickets and Registration <= 5.29.5 - Authenticat… |
stellarwp |
Event Tickets and Registration |
2026-10-02T07:39:28.375Z | 2026-10-02T07:39:28.375Z |
| CVE-2026-96647 |
6.4 (3.1)
|
Listdom: AI-powered Business Directory with Classified… |
webilia |
Listdom: AI-powered Business Directory with Classifieds Ads Listings |
2026-10-02T07:39:28.050Z | 2026-10-02T07:39:28.050Z |
| CVE-2026-95670 |
7.2 (3.1)
|
No External Links <= 5.2.0 - Unauthenticated Stored Cr… |
mihdan |
No External Links |
2026-10-02T07:39:27.705Z | 2026-10-02T07:39:27.705Z |
| CVE-2026-93756 |
7.2 (3.1)
|
Smash Balloon Social Post Feed <= 4.13.0 - Unauthentic… |
smub |
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress |
2026-10-02T07:39:27.358Z | 2026-10-02T07:39:27.358Z |
| CVE-2026-100107 |
7.2 (3.1)
|
Kubio AI Page Builder <= 2.9.2 - Unauthenticated Store… |
extendthemes |
Kubio AI Page Builder |
2026-10-02T07:39:26.996Z | 2026-10-02T07:39:26.996Z |
| CVE-2026-96871 |
7.2 (3.1)
|
Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Sit… |
kitae-park |
Mang Board |
2026-10-02T07:39:26.671Z | 2026-10-02T07:39:26.671Z |
| CVE-2026-97342 |
7.2 (3.1)
|
JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cro… |
jetmonsters |
JetFormBuilder — Dynamic Blocks Form Builder |
2026-10-02T07:39:26.340Z | 2026-10-02T07:39:26.340Z |
| CVE-2026-103426 |
7.2 (3.1)
|
Relevanssi Premium <= 2.31.4 - Unauthenticated Stored … |
Relevanssi |
Relevanssi Premium |
2026-10-02T07:39:25.461Z | 2026-10-02T07:39:25.461Z |
| CVE-2026-96566 |
7.2 (3.1)
|
Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Sit… |
satollo |
Newsletter – Send awesome emails from WordPress |
2026-10-02T07:39:24.588Z | 2026-10-02T07:39:24.588Z |
| CVE-2026-102002 |
3.1 (3.1)
|
Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Se… |
themeisle |
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE |
2026-10-02T07:39:24.233Z | 2026-10-02T07:39:24.233Z |
| CVE-2026-12951 |
6.5 (3.1)
|
MultiVendorX <= 5.0.18 - Authenticated (Store Manager+… |
wcmp |
MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions |
2026-10-02T07:39:23.862Z | 2026-10-02T07:39:23.862Z |
| CVE-2026-100182 |
7.2 (3.1)
|
Download Monitor <= 5.2.10 - Unauthenticated Stored Cr… |
wpchill |
Download Monitor |
2026-10-02T07:39:23.520Z | 2026-10-02T07:39:23.520Z |
| CVE-2026-97641 |
7.2 (3.1)
|
Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Si… |
comesio |
Relevanssi – A Better Search |
2026-10-02T07:39:23.182Z | 2026-10-02T07:39:23.182Z |
| CVE-2026-102772 |
7.2 (3.1)
|
CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scr… |
jtsternberg |
CMB2 |
2026-10-02T07:39:22.836Z | 2026-10-02T07:39:22.836Z |
| CVE-2026-95817 |
7.2 (3.1)
|
DoFollow Case by Case <= 3.6.0 - Unauthenticated Store… |
apasionados |
DoFollow Case by Case |
2026-10-02T07:39:22.487Z | 2026-10-02T07:39:22.487Z |
| CVE-2026-97336 |
7.2 (3.1)
|
CMB2 <= 2.13.0 - Unauthenticated Stored Cross-Site Scr… |
jtsternberg |
CMB2 |
2026-10-02T07:39:22.150Z | 2026-10-02T07:39:22.150Z |
| CVE-2026-93880 |
6.1 (3.1)
|
Greenshift <= 13.2.0 - Reflected Cross-Site Scripting … |
wpsoul |
Greenshift – animation and page builder blocks |
2026-10-02T07:39:21.782Z | 2026-10-02T07:39:21.782Z |
| CVE-2026-96567 |
7.2 (3.1)
|
MW WP Form <= 5.1.7 - Unauthenticated Stored Cross-Sit… |
websoudan |
MW WP Form |
2026-10-02T07:39:21.432Z | 2026-10-02T07:39:21.432Z |
| CVE-2026-96578 |
7.2 (3.1)
|
GSpeech TTS <= 3.22.0 - Unauthenticated Stored Cross-S… |
creative-solutions-1 |
GSpeech TTS – WordPress Text To Speech Plugin |
2026-10-02T07:39:21.086Z | 2026-10-02T07:39:21.086Z |
| CVE-2026-97663 |
7.2 (3.1)
|
Customer Reviews for WooCommerce <= 5.122.0 - Unauthen… |
ivole |
Customer Reviews for WooCommerce |
2026-10-02T07:39:20.600Z | 2026-10-02T07:39:20.600Z |
| CVE-2026-17508 |
5.3 (4.0)
|
Password-based KDF cost parameters honoured unbounded … |
Legion of the Bouncy Castle Inc. |
BC-JAVA |
2026-10-02T07:27:59.519Z | 2026-10-02T07:27:59.519Z |
| CVE-2026-17507 |
8.7 (4.0)
|
MLS membership checks compare a uint32 leaf_index as s… |
Legion of the Bouncy Castle Inc. |
BC-JAVA |
2026-10-02T07:26:34.739Z | 2026-10-02T07:26:34.739Z |
| CVE-2026-103604 |
8.7 (4.0)
|
Quadratic-time escaping when converting X.509 distingu… |
Legion of the Bouncy Castle Inc. |
bc-csharp |
2026-10-02T07:11:04.012Z | 2026-10-02T07:11:04.012Z |
| CVE-2026-103603 |
8.7 (4.0)
|
Unbounded HSS public key level count allows huge array… |
Legion of the Bouncy Castle Inc. |
bc-csharp |
2026-10-02T07:10:34.017Z | 2026-10-02T07:10:34.017Z |
| CVE-2026-103602 |
8.2 (4.0)
|
Name constraints bypass via trailing dot in rfc822Name… |
Legion of the Bouncy Castle Inc. |
bc-csharp |
2026-10-02T07:10:03.885Z | 2026-10-02T07:10:03.885Z |
| CVE-2026-103601 |
8.2 (4.0)
|
CcmBlockCipher and KCcmBlockCipher leave unverified pl… |
Legion of the Bouncy Castle Inc. |
bc-csharp |
2026-10-02T07:09:17.064Z | 2026-10-02T07:09:17.064Z |