🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

375k+ 🇪🇺 EUVD-Datenbank
145 🔴 Critical im Radar
1 ⚠️ CISA KEV
0 🔓 Aktiv ausgenutzt
448 🧪 PoC verfügbar
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
🔴 Criticals pro Monat (12 M) 2025-11: 257 Nov 25 2025-12: 426 2026-01: 431 Jan 26 2026-02: 417 2026-03: 649 Mär 26 2026-04: 574 2026-05: 682 Mai 26 2026-06: 941 2026-07: 1327 Jul 26 2026-08: 1827 2026-09: 1513 Sep 26 2026-10: 397 9.441 Criticals gesamt
🏢 Top-Vendor-Veröffentlichungen (6 M) Apache Software Foundation Google IBM Linux Microsoft Oracle Corporation
● Apache ● Google ● IBM ● Linux ● Microsoft ● Oracle
📈 EPSS-Verteilung (Messungen)
TierCVEsAnteil
≥90 %7200,2 %
≥50 %3.2230,9 %
≥10 %22.1156,0 %
<10 %342.37392,9 %
368.431 CVEs mit EPSS-Score (FIRST.org) · Stand 10.10.2026
Datenquellen & Methodik: Primärquelle ist die EUVD der ENISA (laufender Datenbank-Sync, alle 15 Minuten), abgeglichen mit dem CISA-KEV-Katalog und der NVD — Detail-Dossiers reichern fehlende Felder live per NVD an — mit Fallback auf CIRCL vulnerability-lookup (EU/Non-Profit, aggregiert CVE-, GitHub- und OSV-Advisories). Der CISA-KEV-Katalog (Known Exploited Vulnerabilities, ~1.700 aktiv ausgenutzte Schwachstellen) wird bei jedem Sync vollständig neu geladen und kreuzreferenziert — filterbar über die KEV-Pille. CVSS 3.1 wird nach Ampel-Logik aus Verteidigersicht dekodiert; EPSS bezeichnet die 30-Tage-Exploit-Wahrscheinlichkeit (FIRST.org).
🇪🇺 ENISA EUVD 🇺🇸 NVD ⚠️ CISA KEV ⚡ EPSS
Ökosystem & Hersteller Bedrohungs-Matrix:
Schweregrad & Status:
Hersteller (Datenbank-weit, 99.196 Einträge):
Zeitfenster:
Quelle:
🔍
● 1 Filter aktiv Alles zurücksetzen ✕
– OHNE BEWERTUNG
EPSS
CVE-2026-97396 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97396 | Retainful Email Marketing for WooCommerce Plugin up to 1.0.10 on WordPress data cross site scripting (EUVD-2026-96280)

A vulnerability described as problematic has been identified in Retainful Email Marketing for WooCommerce Plugin up to 1.0.10 on WordPress. This affects an unknown part. Executing a manipulation of the argument data can lead to cross site s

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-96765 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-96765 | WPO365 Plugin up to 44.1 on WordPress id_token cross site scripting (EUVD-2026-96281)

A vulnerability was found in WPO365 Plugin up to 44.1 on WordPress and classified as problematic. Impacted is an unknown function. Such manipulation of the argument id_token leads to cross site scripting. This vulnerability is listed as CVE

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-104803 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-104803 | whyun WPCOM Member Plugin up to 1.7.27 on WordPress Social Login Callback weapp_new_user uuid/code improper authentication (EUVD-2026-96279)

A vulnerability marked as critical has been reported in whyun WPCOM Member Plugin up to 1.7.27 on WordPress. This impacts the function weapp_new_user of the component Social Login Callback Handler. This manipulation of the argument uuid/cod

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-96653 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-96653 | WP Directory Kit Plugin up to 1.5.9 on WordPress Profile Field update_listings_user_editor display_name sql injection (EUVD-2026-96283)

A vulnerability was found in WP Directory Kit Plugin up to 1.5.9 on WordPress. It has been rated as critical. This affects the function WdkCachedUserEditor::update_listings_user_editor of the component Profile Field. The manipulation of the

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-100178 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-100178 | WPAdverts Plugin up to 2.3.4 on WordPress adverts_location cross site scripting (EUVD-2026-96282)

A vulnerability, which was classified as problematic, was found in WPAdverts Plugin up to 2.3.4 on WordPress. This vulnerability affects unknown code. The manipulation of the argument adverts_location results in cross site scripting. This v

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-104728 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-104728 | rubengc AutomatorWP Plugin up to 5.8.4 on WordPress authorization (EUVD-2026-96284)

A vulnerability classified as problematic has been found in rubengc AutomatorWP Plugin up to 5.8.4 on WordPress. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in authorization bypass. This vul

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-102774 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-102774 | BrainstormForce SureDash Plugin up to 1.12.1 on WordPress Post Content cross site scripting (EUVD-2026-96285)

A vulnerability classified as problematic was found in BrainstormForce SureDash Plugin up to 1.12.1 on WordPress. Affected by this issue is some unknown functionality of the component Post Content. Executing a manipulation can lead to cross

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-104759 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-104759 | WPO365 Plugin up to 44.1 on WordPress Deprecated Parser process_openidconnect_token id_token authentication replay (EUVD-2026-96286)

A vulnerability identified as critical has been detected in WPO365 Plugin up to 44.1 on WordPress. The impacted element is the function Id_Token_Service_Deprecated::process_openidconnect_token of the component Deprecated Parser. The manipul

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-102291 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-102291 | meum Kirki Plugin up to 6.3.1 on WordPress Shortcode Execution replace_content display_name command injection (EUVD-2026-96287)

A vulnerability labeled as critical has been found in meum Kirki Plugin up to 6.3.1 on WordPress. This affects the function TheFrontend::replace_content of the component Shortcode Execution. The manipulation of the argument display_name res

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-97340 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-97340 | meFusion Avada up to 7.16.1 on WordPress Author Page get_markup cross site scripting (EUVD-2026-96288)

A vulnerability was found in meFusion Avada up to 7.16.1 on WordPress. It has been declared as problematic. The impacted element is the function Fusion_Social_Icon::get_markup of the component Author Page. Executing a manipulation of the ar

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-93746 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-93746 | WebToffee PDF Invoices Packing Slips Delivery Notes & Shipping Labels Plugin print_document_from_the_mail_link resource injection (EUVD-2026-96289)

A vulnerability categorized as problematic has been discovered in WebToffee PDF Invoices Packing Slips Delivery Notes &amp;amp; Shipping Labels Plugin up to 5.0.2 on WordPress. This impacts the function print_document_from_the_mail_link. Th

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-103478 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-103478 | codename065 Premium Packages Plugin up to 7.2.6 on WordPress phone/state/taxid/email cross site scripting (EUVD-2026-96290)

A vulnerability was found in codename065 Premium Packages Plugin up to 7.2.6 on WordPress. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation of the argument phone/state/taxid/email

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS
CVE-2026-93951 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
WordPress

CVE-2026-93951 | Bracketweb Zeinet Plugin up to 1.0.0 on WordPress cross site scripting (EUVD-2026-96291)

A vulnerability classified as problematic has been found in Bracketweb Zeinet Plugin up to 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability is uniquely identifie

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Plugin / Theme im WP-Dashboard auf die neueste Version aktualisieren oder temporär deaktivieren.
– OHNE BEWERTUNG
EPSS 0.5%
CVE-2026-40345 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-40345 | RebeccaStevens deepmerge-ts up to 7.x stack-based overflow (WID-SEC-2026-3831)

A vulnerability categorized as problematic has been discovered in RebeccaStevens deepmerge-ts up to 7.x. This affects the function deepmerge/deepmergeCustom/deepmergeInto/deepmergeIntoCustom. The manipulation results in stack-based buffer o

CWE-119: Memory Corruption ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 12.7%
CVE-2018-14718 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-14718 | Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0 jackson-databind deserialization (ID 176635 / BID-106601)

A vulnerability, which was classified as critical, has been found in Oracle JDeveloper 12.1.3.0.0/12.2.1.3.0. This affects an unknown function of the component jackson-databind. This manipulation causes deserialization. This vulnerability a

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.3%
CVE-2018-12120 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-12120 | Node.js up to 6.14.x Debugger --debug=localhost 7pk security (Nessus ID 119511 / ID 172114)

A vulnerability described as critical has been identified in Node.js up to 6.14.x. Affected is an unknown function of the component Debugger. Executing a manipulation of the argument --debug=localhost can lead to 7pk security features. This

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.6%
CVE-2018-12116 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-12116 | Node.js up to 6.14.x/8.13.x HTTP Request request smuggling (Nessus ID 119511 / ID 172114)

A vulnerability marked as critical has been reported in Node.js up to 6.14.x/8.13.x. This impacts an unknown function of the component HTTP Request Handler. Performing a manipulation results in http request smuggling. This vulnerability is

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 4.1%
CVE-2018-1000880 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-1000880 | libarchive 3.2.0 archive_read_support_format_warc.c warc_read Archive double free (USN-3859-1 / Nessus ID 119893)

A vulnerability has been found in libarchive 3.2.0 and classified as problematic. The impacted element is the function warc_read of the file libarchive/archive_read_support_format_warc.c. The manipulation as part of Archive leads to double

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.4%
CVE-2018-1000879 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-1000879 | libarchive 3.3.0 libarchive/archive_acl.c archive_acl_from_text_l null pointer dereference (FEDORA-2019-0233ec0ff3 / ID 277759)

A vulnerability, which was classified as problematic, was found in libarchive 3.3.0. The affected element is the function archive_acl_from_text_l of the file libarchive/archive_acl.c. Executing a manipulation can lead to null pointer derefe

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.4%
CVE-2026-88776 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776)

Citrix NetScaler ADC and Gateway: eight advisories, two under active exploitation (CVE-2026-88776) The Dutch national cyber security centre published NCSC-2026-0394 on 27 September 2026 with a High priority rating. The subject is a single h

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 3.4%
CVE-2018-5407 💻 Lokal 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-5407 | CPU Multi-Threading Timing information disclosure (RHSA-2019:0483 / EDB-45785)

A vulnerability described as critical has been identified in CPU. The impacted element is an unknown function of the component Multi-Threading. The manipulation as part of Timing results in information disclosure. This vulnerability is iden

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 12.2%
CVE-2018-0734 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2018-0734 | Oracle Enterprise Session Border Controller up to 8.3 Security key management (Nessus ID 211827 / ID 20103)

A vulnerability labeled as critical has been found in Oracle Enterprise Session Border Controller 7.5/8.0/8.1/8.2/8.3. This impacts an unknown function of the component Security. Such manipulation leads to key management error. This vulnera

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS 0.3%
CVE-2026-77166 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

CVE-2026-77166 | Nextcloud Collectives up to 3.5.0 Page Emoji Update Endpoint emoji injection (WID-SEC-2026-3840)

A vulnerability has been found in Nextcloud Collectives up to 3.5.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Page Emoji Update Endpoint. This manipulation of the argument emoji cau

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
– OHNE BEWERTUNG
EPSS
CVE-PENDING 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
Generic Security

Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers

Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed backup servers without authentication and execute commands with SYSTEM privileges. Observed intrusions have deployed web

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-96667 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
rameez_iqbal

CVE-2026-96667 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The reCAPTCHA check is trivially bypassed by

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 7.3 due to insufficient input sanitizatio

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-94375 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
webtoffee

CVE-2026-94375 | The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to extract download exported order CSV files containing customer PII — including names, billing and shipping addresses, email addresses, phone numbers, and order contents — directly over HTTP with no authentication. This is ex

The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8 via the get_file_path. This makes it possible for unauthenticated attackers to

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.9 MEDIUM
EPSS
CVE-2026-104763 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
wpazleen

CVE-2026-104763 | The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This requires the attacker to upload a crafted ZIP archive containing a media_metadata.json f

The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with admin

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-104725 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
trainingbusinesspros

CVE-2026-104725 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter within the `process_edit()` function, which allows any authenticated user with the `edit_contacts` capability to reassign a contact record's linked WordPress user ID to any arbitrary account without requiring the `edit_us

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9 This is due to a missing ownership and capability check on the `user` parameter

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-103520 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
HivePress

CVE-2026-103520 | The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whe

The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including,

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-83526 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Foliovision

CVE-2026-83526 | The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes attacker-supplied remote file content to the public uploads directory before any MIME or extension check, combined with a missing capability check on new player creation. This makes it possible for authenticated attackers, with

The FV Player 8 plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.1.7 via the check_mimetype function. This is due to insufficient file type validation in check_mimetype(), which writes atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-16776 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
sonaar

CVE-2026-16776 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Wo

The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.14.2 due to insufficient input sanitiza

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-14379 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
rubengc

CVE-2026-14379 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user a

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due t

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
8.8 HIGH
EPSS
CVE-2026-104766 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
latepoint

CVE-2026-104766 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` handler iterating over attacker-supplied `settings` parameters without an allowlist of permitted setting names or values, and `OsSettingsHelper::prepare_value()` performing no role allowlist validation before persisting the `

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.7.3. This is due to the `OsSettingsController::update()` han

CWE-269: Privilege Management ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
3.1 LOW
EPSS
CVE-2026-104742 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
senols

CVE-2026-104742 | The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global site-wide semantic search settings, including vector provider, embedding provider, embeddin

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-78068 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
jonua

CVE-2026-78068 | The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell Content in all versions up to, and including, 1.3.35 due to insufficient input sanitization and output escaping. This ma

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
3.1 LOW
EPSS
CVE-2026-104741 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
senols

CVE-2026-104741 | The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global plugin indexing and vector-search configuration options (aipkit_training_general_settings a

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.9 MEDIUM
EPSS
CVE-2026-104023 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
supsysticcom

CVE-2026-104023 | The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to ext

The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter and lack of sufficien

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.3 MEDIUM
EPSS
CVE-2026-91050 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
latepoint

CVE-2026-91050 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publicly reachable steps__start and steps__load_step routes accepting a params[presets][order_item_id] value that is copied verbatim into the booking object without verifying that the referenced order item belongs to the curren

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference / Missing Authorization in versions up to, and including, 5.7.2. This is due to the publ

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-18496 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
wpdevelop

CVE-2026-18496 | The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.4.3 via the wpbc_is_show_popover_in_flex_timeline() function. This makes it possible for unauthenticated attackers to extract sensitive data including names, email addresses, and phone numbers of customers who have made bookings.

The Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.4.3 via the wpbc_is_show_popover_in_flex_timeline() function. This makes it possible for unauthenticated atta

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.5 HIGH
EPSS
CVE-2026-89301 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
rtCamp

CVE-2026-89301 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possible for unauthenticated attackers to delete arbitrary safe files on the server.. The public nonce (rtmedia_upload_nonce) is emitted into frontend JavaScript on any page rendering the rtMedia gallery or upload shortcode, maki

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to limited file deletion due to insufficient file path validation in the process function in all versions up to, and including, 4.7.13 This makes it possib

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.1 CRITICAL
EPSS
CVE-2026-97670 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
ThemeFusion

CVE-2026-97670 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data token; the 3.16.1 trust gate is_content_request_supplied() only ins

The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook wh

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
7.2 HIGH
EPSS
CVE-2026-104021 🌐 Netzwerk (Remote) 🔐 Admin-Rechte nötig
hostspa

CVE-2026-104021 | The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cookie_exclude` setting via `register_setting()` without a `sanitize_callback`, while `buildSiteHtaccessRules()` applies only `trim()` to each cookie value before interpolating it directly into an Apache `RewriteCond` line — a

The Fastcache by Host.it plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.7.4 via the `fastcache_settings[cache_cookie_exclude][]` parameter. This is due to the plugin registering the `cache_cooki

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-9696 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
codename065

CVE-2026-9696 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'not_found' parameter in all versions up to, and including, 3.3.58 due to insufficient input sanitization and output escaping. This makes it poss

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-104724 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
FirePlugins

CVE-2026-104724 | The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to generic SQL Injection via FireBox Form Display Condition in all versions up to, and including, 3.1.13 due to in

CWE-89: SQL Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.1 MEDIUM
EPSS
CVE-2026-103998 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
10web

CVE-2026-103998 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inputs (array key)' parameter in all versions up to, and including, 1.15.48 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action su

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inputs (array key)' parameter in all versions up to, and including, 1.15.48 due to insu

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.3 MEDIUM
EPSS
CVE-2026-6723 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
croixhaug

CVE-2026-6723 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API endpoint not restricting which fields can be modified by token-authenticated customers. This makes it possible for unauthenticated attackers to modify admin-controlled fields on that appointment, including faking payment confir

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 1.6.11.11. This is due to the appointment update REST API end

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.4 MEDIUM
EPSS
CVE-2026-103424 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
cleantalk

CVE-2026-103424 | The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is exploitable once a comment

The Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 6.88 due to insufficient input sanitization and

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.1 MEDIUM
EPSS
CVE-2026-87869 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
stepasyuk

CVE-2026-87869 | The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the flrt_elementor_load_more_anchor() function. The function reads query parameters from $_SERVER['REQUEST_URI'] via getFormActionOrFullPageUrl(true), which URL-decodes them through parse_str() and re-assembles them using build

The Filter Everything — WordPress & WooCommerce Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.9.6. This is due to insufficient input sanitization and output escaping in the

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-104735 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
themeisle

CVE-2026-104735 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS <title> in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execu

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Feedzy Loop Block Feed URL / RSS in all versions up to, and including, 5

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.3 MEDIUM
EPSS
CVE-2026-103964 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
codename065

CVE-2026-103964 | The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the administrator's full Cookie header, including wordpress_logged_in_* session cookies, from the suspension email sent during the administrator's authenticated request, enabling full session

The Download Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.71 via the 'first_name' parameter. This makes it possible for authenticated attackers, with subscriber-level

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-97630 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
Foliovision

CVE-2026-97630 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output esca

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.4 MEDIUM
EPSS
CVE-2026-5727 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
elemntor

CVE-2026-5727 | The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to publish their own Hello+ header/footer templates and draft currently active templates owned by higher-privileged users.

The Hello Plus plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible f

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-102401 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
codename065

CVE-2026-102401 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload only fires for logged-out s

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regurl' parameter in all versions up to, and including, 3.3.71 due to insufficient input sanitization and output escaping. This makes it possibl

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS
CVE-2026-103889 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
expivi

CVE-2026-103889 | The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution enabled. This makes it possible for unauthen

The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce ch

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
4.7 MEDIUM
EPSS
CVE-2026-101324 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
wpmanageninja

CVE-2026-101324 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses 'proof')' parameter in all versions up to, and including, 6.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'any attacker-chosen name matching the {get.NAME} placeholder (PoC uses

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-96648 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
supsysticcom

CVE-2026-96648 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is o

The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Table Cell 'data' Value via updateRows Action in all versions up to, and including, 1.15.1 due to insufficient input sanitization a

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
6.4 MEDIUM
EPSS
CVE-2026-104993 🌐 Netzwerk (Remote) 🔑 Geringe Nutzerrechte nötig
paoltaia

CVE-2026-104993 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that wi

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, a

CWE-79: Cross-Site Scripting ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
5.7 MEDIUM
EPSS
CVE-2026-108501 🌐 Adjacent Network 🔓 Keine Authentifizierung nötig
ZTE

CVE-2026-108501 | ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface.

ZTE Z80 Ultra has a system interface permission verification defect. The interface lacks necessary access control, and relevant information can be read by reflectively invoking the interface.

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS
CVE-2026-94589 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
htplugins

CVE-2026-94589 | The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shel

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to miss

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
9.8 CRITICAL
EPSS
CVE-2026-104732 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig
IniLerm

CVE-2026-104732 | The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error branch in the function unconditionally min

The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, sessio

CWE-287: Improper Authentication ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.
60 von ~1.224 Einträgen geladen