7.5

CVSS3.1

CVE-2026-22401 - WordPress Freshio theme <= 2.4.2 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in pavothemes Freshio freshio allows PHP Local File Inclusion.This issue affects Freshio: from n/a through <= 2.4.2.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:27 p.m.

5.4

CVSS3.1

CVE-2026-22400 - WordPress Holmes theme <= 1.7 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Holmes holmes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Holmes: from n/a through <= 1.7.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:27 p.m.

5.4

CVSS3.1

CVE-2026-22398 - WordPress Fleur theme <= 2.0 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fleur fleur allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fleur: from n/a through <= 2.0.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:27 p.m.

5.4

CVSS3.1

CVE-2026-22396 - WordPress Fiorello theme <= 1.0 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Fiorello fiorello allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fiorello: from n/a through <= 1.0.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:27 p.m.

5.4

CVSS3.1

CVE-2026-22393 - WordPress Curly theme <= 3.3 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Curly curly allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Curly: from n/a through <= 3.3.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:27 p.m.

5.4

CVSS3.1

CVE-2026-22391 - WordPress Cocco theme <= 1.5.1 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Cocco cocco allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cocco: from n/a through <= 1.5.1.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 6:27 p.m.

5.9

CVSS3.1

CVE-2026-22388 - WordPress Owl Carousel WP plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu Owl Carousel WP owl-carousel-wp allows Stored XSS.This issue affects Owl Carousel WP: from n/a through <= 2.2.2.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 8 a.m.

5.4

CVSS3.1

CVE-2026-22382 - WordPress PawFriends - Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Cross Site Request Foโ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6 p.m.

4.3

CVSS3.1

CVE-2026-22360 - WordPress SearchAzon plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in AA-Team SearchAzon searchazon allows Cross Site Request Forgery.This issue affects SearchAzon: from n/a through <= 1.4.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 3:45 a.m.

5.4

CVSS3.1

CVE-2026-22358 - WordPress Electrician - Electrical Service WordPress theme <= 5.6 - Server Side Request Forgery (SSโ€ฆ

Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Electrician - Electrical Service WordPress electrician allows Server Side Request Forgery.This issue affects Electrician - Electrical Service WordPress: from n/a through <= 5.6.

๐Ÿ“… Published: Jan. 22, 2026, 4:52 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 8 a.m.
Total resulsts: 346536
Page 1736 of 34,654
ยซ previous page ยป next page
Filters