0.0

CVE-2026-25697 -

Not used

๐Ÿ“… Published: Feb. 5, 2026, 8:56 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25694 -

Not used

๐Ÿ“… Published: Feb. 5, 2026, 8:56 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25692 -

Not used

๐Ÿ“… Published: Feb. 5, 2026, 8:56 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

0.0

CVE-2026-25693 -

Not used

๐Ÿ“… Published: Feb. 5, 2026, 8:56 a.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 3:55 a.m.

4.3

CVSS3.1

CVE-2025-13416 - ProfileGrid โ€“ User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticโ€ฆ

The ProfileGrid โ€“ User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 8:25 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:15 p.m.

6.4

CVSS3.1

CVE-2026-1319 - Robin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Alteโ€ฆ

The Robin Image Optimizer โ€“ Unlimited Image Optimization & WebP Converter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of a Media Library image in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escapinโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 8:25 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 9:30 p.m.

5.1

CVSS4.0

CVE-2026-25198 - Open Redirect Vulnerability Enabling Phishing in web2py

web2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an open redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website when accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

๐Ÿ“… Published: Feb. 5, 2026, 7:38 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:15 p.m.

6.3

CVSS3.1

CVE-2025-10258 - A time-based SQL Injection vulnerability in Infinera DNA

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.

๐Ÿ“… Published: Feb. 5, 2026, 7:13 a.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 10:20 p.m.

6.4

CVSS3.1

CVE-2026-1268 - Dynamic Widget Content <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widgโ€ฆ

The Dynamic Widget Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget content field in the Gutenberg editor sidebar in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes itโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 6:47 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-0867 - Essential Widgets <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shโ€ฆ

The Essential Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ew-author, ew-archive, ew-category, ew-page, and ew-menu shortcodes in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping on user supplied attributโ€ฆ

๐Ÿ“… Published: Feb. 5, 2026, 6:47 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 9:30 p.m.
Total resulsts: 346563
Page 1529 of 34,657
ยซ previous page ยป next page
Filters