Vulnerabilities (CVE)

Total 398517 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-73183 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-73386 2026-08-20 N/A 7.5 HIGH
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
CVE-2026-66651 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.
CVE-2026-73182 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
CVE-2026-32472 2026-08-20 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
CVE-2026-32463 2026-08-20 N/A 9.9 CRITICAL
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-32465 2026-08-20 N/A 8.8 HIGH
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
CVE-2026-66636 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.
CVE-2026-66667 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
CVE-2026-61986 2026-08-20 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
CVE-2026-32468 2026-08-20 N/A 7.5 HIGH
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
CVE-2026-32549 2026-08-20 N/A 7.5 HIGH
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
CVE-2026-66639 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.
CVE-2026-73391 2026-08-20 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-68565 2026-08-20 N/A 6.5 MEDIUM
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
CVE-2026-73394 2026-08-20 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
CVE-2026-73399 2026-08-20 N/A 6.5 MEDIUM
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
CVE-2026-73341 2026-08-20 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
CVE-2026-32474 2026-08-20 N/A 9.9 CRITICAL
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVE-2026-73350 2026-08-20 N/A 8.2 HIGH
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.