6.1

CVSS3.1

CVE-2026-1127 - Timeline Event History <= 3.2 - Reflected Cross-Site Scripting

The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-13194 - SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any compl…

The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce verification on the 'SurveyJS_RenameSurvey' AJAX ac…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 22, 2026, midnight

4.4

CVSS3.1

CVE-2026-1191 - JavaScript Notifier <= 1.2.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugi…

The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 1.2.8. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the `wp_footer` action. This makes it possible…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 16, 2026, 1:30 a.m.

4.3

CVSS3.1

CVE-2026-1208 - Friendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery to Settings Update

The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the settings page. This makes it possible for unauthenticated attackers to update plugin settings …

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2026-1189 - LeadBI Plugin for WordPress <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via '…

The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' parameter of the 'leadbi_form' shortcode in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 16, 2026, 1:30 a.m.

4.4

CVSS3.1

CVE-2026-1300 - Responsive Header Plugin <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Se…

The Responsive Header plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple plugin settings parameters in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrato…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

4.3

CVSS3.1

CVE-2025-13139 - SurveyJS: Drag & Drop WordPress Form Builder <= 2.5.2 - Cross-Site Request Forgery to Survey Creati…

The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to missing nonce validation on the SurveyJS_AddSurvey AJAX action. This makes it possible for unauthenticated attackers to creat…

📅 Published: Jan. 24, 2026, 9:08 a.m. 🔄 Last Modified: April 22, 2026, 3:45 p.m.

6.4

CVSS3.1

CVE-2026-1098 - CM CSS Columns <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortc…

The CM CSS Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' shortcode attribute in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: Jan. 24, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.

3.7

CVSS3.1

CVE-2026-0633 - MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticate…

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0. This is due to the use of a forgeable cookie value derived only from the entry ID and current user ID without a…

📅 Published: Jan. 24, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2026-1302 - Meta-box GalleryMeta <= 3.0.1 - Authenticated (Editor+) Stored Cross-Site Scripting via Image Capti…

The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and…

📅 Published: Jan. 24, 2026, 8:26 a.m. 🔄 Last Modified: April 15, 2026, 9:45 p.m.
Total resulsts: 349182
Page 1957 of 34,919
« previous page » next page
Filters