Vulnerabilities
Summary — last 7 days
New vulnerabilities2,729▼ 513 vs. last week
Critical / high1,298▼ 212 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
68 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.1) | 0.29% | — | Maximevalette Ical FeedsAI | 4/17/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maximevalette iCal Feeds ical-feeds allows Reflected XSS.This issue affects iCal Feeds: from n/a through <= 1.5.3. | |
| Analyzed | Medium (4.8) | 0.27% | — | Patelmilap Widget FOR Social Page Feeds | 4/15/2025 | 6/17/2026 | The Widget for Social Page Feeds WordPress plugin before 6.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Deferred | Medium (4.3) | 0.21% | — | Flyaga FIX RSS FeedsAI | 3/24/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in flyaga Fix Rss Feeds fix-rss-feed allows Cross Site Request Forgery.This issue affects Fix Rss Feeds: from n/a through <= 3.1. | |
| Deferred | Medium (4.3) | 0.20% | — | Smashballoon Custom Twitter FeedsAI | 3/20/2025 | 6/17/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it possible for unauthenticated attackers to… | |
| Deferred | High (7.1) | 0.30% | — | Titodevera Awesome Twitter FeedsAI | 3/3/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titodevera Awesome Twitter Feeds awesome-twitter-feeds allows Reflected XSS.This issue affects Awesome Twitter Feeds: from n/a through <= 1.0. | |
| Deferred | Medium (5.3) | 0.38% | — | Rebelcode Spotlight Social Media FeedsAI | 2/17/2025 | 6/17/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RebelCode Spotlight Social Media Feeds spotlight-social-photo-feeds allows Retrieve Embedded Sensitive Data.This issue affects Spotlight Social Media Feeds: from n/a through <= 1.7.1. | |
| Deferred | Medium (6.5) | 0.32% | — | Parone INC Parone FeedsAI | 11/19/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ParOne, Inc ParOne Feeds parone allows DOM-Based XSS.This issue affects ParOne Feeds: from n/a through <= 1.17.1. | |
| Modified | High (8.8) | 0.19% | — | Smashballoon Custom Twitter Feeds | 10/31/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through <= 2.2.3. | |
| Analyzed | Medium (4.8) | 0.43% | — | Smashballoon Custom Twitter Feeds | 10/8/2024 | 6/17/2026 | Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modified | Medium (5.4) | 0.42% | — | Smashballoon Feeds FOR Youtube | 7/11/2024 | 6/17/2026 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Deferred | Medium (4.3) | 0.20% | — | Rebelcode Spotlight Social Media FeedsAI | 4/15/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RebelCode Spotlight Social Media Feeds.This issue affects Spotlight Social Media Feeds: from n/a through 1.6.10. | |
| Deferred | High (7.2) | 0.60% | — | Mooveagency Import XML AND RSS FeedsAI | 4/7/2024 | 6/17/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5. | |
| Deferred | Medium (6.5) | 0.32% | — | Augustinfotech AI Twitter FeedsAI | 3/31/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in August Infotech AI Twitter Feeds (Twitter widget & shortcode) allows Stored XSS.This issue affects AI Twitter Feeds (Twitter widget & shortcode): from n/a through 2.4. | |
| Analyzed | Medium (6.1) | 0.40% | — | Patelmilap Widget FOR Social Page Feeds | 3/18/2024 | 6/17/2026 | The Widget for Social Page Feeds WordPress plugin before 6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modified | Medium (4.8) | 0.38% | — | Shahaji9 Advanced Social Feeds Widget & Shortcode | 3/18/2024 | 6/17/2026 | The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modified | Medium (4.3) | 1.00% | 💥 PoC | Smashballoon Custom Twitter Feeds | 2/29/2024 | 6/17/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to… | |
| Modified | High (8.8) | 0.22% | — | Smashballoon Custom Twitter Feeds | 1/5/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds – A Tweets Widget or X Feed Widget.This issue affects Custom Twitter Feeds – A Tweets Widget or X Feed Widget: from n/a through 2.1.2. | |
| Modified | Medium (5.3) | 0.50% | — | Blmodules CSV Feeds PRO | 11/27/2023 | 6/17/2026 | In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of… | |
| Modified | Critical (9.8) | 0.64% | — | Blmodules CSV Feeds PRO | 10/31/2023 | 6/17/2026 | In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modified | Critical (9.8) | 41% | 💥 Exploit | Mooveagency Import XML AND RSS Feeds | 9/25/2023 | 6/17/2026 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue (https://wpscan.com/vulnerability/d4220025-2272-4d5f-9703-4b2ac4a51c42)… | |
| Modified | High (7.2) | 2.0% | 💥 PoC | Mooveagency Import XML AND RSS Feeds | 9/25/2023 | 6/17/2026 | The Import XML and RSS Feeds WordPress plugin before 2.1.4 does not filter file extensions for uploaded files, allowing an attacker to upload a malicious PHP file, leading to Remote Code Execution. | |
| Modified | Critical (9.8) | 0.81% | — | Blmodules Xmlfeeds PRO | 9/15/2023 | 6/17/2026 | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds(). | |
| Modified | Medium (5.4) | 0.55% | — | Smashballoon Feeds FOR Youtube | 9/14/2023 | 6/17/2026 | The Feeds for YouTube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube-feed' shortcode in versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modified | High (8.8) | 0.25% | — | Smashballoon Custom Twitter Feeds | 5/29/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions. | |
| Modified | Medium (4.8) | 0.39% | — | Winwar WP Ebay Product Feeds | 3/23/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP eBay Product Feeds plugin <= 3.3.1 versions. |