9.3

CVSS4.0

CVE-2026-3010 - TimePictra Stored Cross-Site Scripting

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.

๐Ÿ“… Published: Feb. 28, 2026, 11:45 a.m. ๐Ÿ”„ Last Modified: Feb. 28, 2026, 11:45 a.m.

9.3

CVSS4.0

CVE-2026-2844 - TimePictra Authentication Bypass Vulnerability

Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.

๐Ÿ“… Published: Feb. 28, 2026, 11:44 a.m. ๐Ÿ”„ Last Modified: Feb. 28, 2026, 11:44 a.m.

7.5

CVSS3.1

CVE-2025-13673 - Tutor LMS <= 3.9.6 - Unauthenticated SQL Injection via coupon_code

The Tutor LMS โ€“ eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL queโ€ฆ

๐Ÿ“… Published: Feb. 28, 2026, 7:25 a.m. ๐Ÿ”„ Last Modified: Feb. 28, 2026, 7:25 a.m.

7.5

CVSS3.1

CVE-2026-2471 - WP Mail Logging <= 1.15.0 - Unauthenticated PHP Object Injection via Email Log Message Field

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. This is due to the `BaseModel` class constructor calling `maybe_unserialize()` on all properties retriโ€ฆ

๐Ÿ“… Published: Feb. 28, 2026, 6:27 a.m. ๐Ÿ”„ Last Modified: Feb. 28, 2026, 6:27 a.m.

0.0

CVE-2026-1542 - Super Stage WP <= 1.0.1 - Unauthenticated PHP Object Injection

The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.

๐Ÿ“… Published: Feb. 28, 2026, 6 a.m. ๐Ÿ”„ Last Modified: Feb. 28, 2026, 6 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri ร‡ilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genรง

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali ฤฐltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here