| CVE-2026-19754 | NA | N/A | Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authent… | 2026-09-02 |
| CVE-2026-3851 | MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's le… | 2026-09-02 |
| CVE-2024-35585 | HIGH | 8.6 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.… | 2026-09-02 |
| CVE-2025-46418 | HIGH | 7.6 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.… | 2026-09-02 |
| CVE-2026-9055 | CRITICAL | 9.8 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Priv… | 2026-09-02 |
| CVE-2025-15663 | MEDIUM | 6.8 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the … | 2026-09-02 |
| CVE-2025-15664 | MEDIUM | 6.8 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the … | 2026-09-02 |
| CVE-2026-12526 | HIGH | 8.1 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is aut… | 2026-09-02 |
| CVE-2026-12865 | HIGH | 7.1 | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before refle… | 2026-09-02 |
| CVE-2026-14215 | MEDIUM | 6.5 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authenticatio… | 2026-09-02 |
| CVE-2026-14357 | HIGH | 8.8 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2… | 2026-09-02 |
| CVE-2026-15232 | MEDIUM | 5.3 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership… | 2026-09-02 |
| CVE-2026-16966 | MEDIUM | 5.3 | The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one… | 2026-09-02 |
| CVE-2026-16983 | MEDIUM | 4.3 | The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST … | 2026-09-02 |
| CVE-2026-19116 | HIGH | 8.8 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deser… | 2026-09-02 |
| CVE-2026-19251 | MEDIUM | 5.3 | The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whe… | 2026-09-02 |
| CVE-2026-19453 | HIGH | 7.1 | The JetBackup WordPress plugin before 3.1.23.5 does not verify the role or capabilities of the account it pre… | 2026-09-02 |
| CVE-2026-19704 | MEDIUM | 5.3 | The Comments WordPress plugin before 7.6.66 does not validate a value used to build a database query, allowin… | 2026-09-02 |
| CVE-2026-19719 | MEDIUM | 6.8 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post t… | 2026-09-02 |
| CVE-2026-19723 | HIGH | 7.1 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a… | 2026-09-02 |
| CVE-2026-74927 | MEDIUM | 5.3 | The MultiVendorX WordPress plugin before 5.0.15 does not have proper authorisation controls on one of its RES… | 2026-09-02 |
| CVE-2026-77764 | MEDIUM | 4.3 | The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionali… | 2026-09-02 |
| CVE-2026-77782 | MEDIUM | 5.3 | The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a post is password protected befor… | 2026-09-02 |
| CVE-2026-77783 | LOW | 3.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on th… | 2026-09-02 |
| CVE-2026-77784 | LOW | 2.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object b… | 2026-09-02 |
| CVE-2026-77785 | LOW | 2.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to re… | 2026-09-02 |
| CVE-2026-77787 | LOW | 2.7 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata upda… | 2026-09-02 |
| CVE-2026-77788 | MEDIUM | 4.9 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the metadata row being updated belongs… | 2026-09-02 |
| CVE-2026-77792 | HIGH | 7.5 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before … | 2026-09-02 |
| CVE-2026-78151 | MEDIUM | 5.3 | The FormLayer WordPress plugin before 1.0.9 does not perform any authorization check before returning a form's… | 2026-09-02 |
| CVE-2026-78657 | CRITICAL | 9.8 | The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to i… | 2026-09-02 |
| CVE-2026-79621 | MEDIUM | 4.3 | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user c… | 2026-09-02 |
| CVE-2026-80467 | HIGH | 8.1 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted thro… | 2026-09-02 |
| CVE-2026-81194 | MEDIUM | 4.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization wh… | 2026-09-02 |
| CVE-2026-81195 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b… | 2026-09-02 |
| CVE-2026-81196 | LOW | 2.7 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of qui… | 2026-09-02 |
| CVE-2026-81197 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not restrict access to a REST route … | 2026-09-02 |
| CVE-2026-81198 | LOW | 3.8 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a c… | 2026-09-02 |
| CVE-2026-81199 | MEDIUM | 5.3 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not perform an authorization check b… | 2026-09-02 |
| CVE-2026-81426 | MEDIUM | 4.3 | The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order s… | 2026-09-02 |
| CVE-2026-81427 | MEDIUM | 4.3 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order s… | 2026-09-02 |
| CVE-2026-81428 | MEDIUM | 6.5 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownership or the object type of user-supplied … | 2026-09-02 |
| CVE-2026-81432 | MEDIUM | 4.3 | The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its A… | 2026-09-02 |
| CVE-2026-81583 | MEDIUM | 5.4 | The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processin… | 2026-09-02 |
| CVE-2026-81737 | HIGH | 8.8 | The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or escape content submitted by unauthentic… | 2026-09-02 |
| CVE-2026-81807 | HIGH | 8.8 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering i… | 2026-09-02 |
| CVE-2026-82182 | MEDIUM | 4.1 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied li… | 2026-09-02 |
| CVE-2026-82183 | HIGH | 8.1 | The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify the identity assertion returned by its… | 2026-09-02 |
| CVE-2026-3850 | MEDIUM | 6.4 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of … | 2026-09-02 |
| CVE-2026-82883 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus L… | 2026-09-02 |