9.8

CVSS3.1

CVE-2026-1357 - Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

The Migration, Backup, Staging โ€“ WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path sanitization when writinโ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 5:30 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:15 p.m.

6.4

CVSS3.1

CVE-2026-1893 - Orbisius Random Name Generator <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting โ€ฆ

The Orbisius Random Name Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_label' parameter in the 'orbisius_random_name_generator' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it โ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 4:36 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 6:45 p.m.

4.7

CVSS3.1

CVE-2026-26079 - roundcubemail: Roundcube Webmail: Cascading Style Sheets (CSS) injection via mishandled comments

Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.

๐Ÿ“… Published: Feb. 11, 2026, 4:27 a.m. ๐Ÿ”„ Last Modified: April 17, 2026, 8:30 p.m.

7.2

CVSS3.1

CVE-2025-14541 - Lucky Wheel Giveaway <= 1.0.22 - Authenticated (Administrator+) Remote Code Execution via 'conditioโ€ฆ

The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.22 via the conditional_tags parameter. This is due to the plugin using PHP's eval() function on user-controlled input without proper validation or sanitization. This makes โ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 1:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-13431 - SlimStat Analytics <= 5.3.1 - Authenticated (Subscriber+) SQL Injection via `args` Parameter

The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜argsโ€™ parameter in all versions up to, and including, 5.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possiblโ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 1:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2026-1231 - Beaver Builder Page Builder โ€“ Drag and Drop Website Builder <= 2.10.0.5 - Authenticated (Custom+) Mโ€ฆ

The Beaver Builder Page Builder โ€“ Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `js` Global Settings parameter in all versions up to, and including, 2.10.0.5 due to missing capability checks on save_global_settings() function and insufficienโ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 1:23 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 6:45 p.m.

4.3

CVSS3.1

CVE-2025-15524 - Gallery by FooGallery <= 3.1.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Galโ€ฆ

The Gallery by FooGallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax_get_gallery_info() function in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and aboโ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 1:23 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 3:45 p.m.

0.0

CVE-2026-2326 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: Feb. 11, 2026, 12:49 a.m. ๐Ÿ”„ Last Modified: March 16, 2026, 11:59 a.m.

5.3

CVSS4.0

CVE-2026-1571 - Reflected XSS Vulnerability on TP-Link Archer C60

User-controlled input is reflected into the HTML output without proper encoding on TP-Link Archer C60 v3, allowing arbitrary JavaScript execution via a crafted URL.ย An attacker could run script in the device web UI context, potentially enabling credential theft, session hijacking, or unintended actโ€ฆ

๐Ÿ“… Published: Feb. 11, 2026, 12:39 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 5:30 p.m.

5.3

CVSS3.1

CVE-2024-26478 -

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/users endpoint.

๐Ÿ“… Published: Feb. 11, 2026, midnight ๐Ÿ”„ Last Modified: Feb. 26, 2026, 9:22 p.m.
Total resulsts: 349182
Page 1694 of 34,919
ยซ previous page ยป next page
Filters