Vulnerabilities
Summary — last 7 days
New vulnerabilities2,568▼ 306 vs. last week
Critical / high1,351▲ 96 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
15 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (4.9) | 0.44% | — | Servit Affiliate-toolkitAI | 8/14/2026 | 8/14/2026 | The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.8.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Deferred | Medium (6.4) | 0.35% | — | Affiliate-toolkit WP Affiliate Plugin With Amazon PluginAI | 7/10/2026 | 7/14/2026 | The affiliate-toolkit – WP Affiliate Plugin with Amazon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'atkp_product' shortcode in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Deferred | High (7.2) | 1.1% | — | Servit Affiliate-toolkitAI | 5/27/2026 | 6/17/2026 | The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 3.8.5. This is due to the plugin using the BladeOne templating engine's runString() method which compiles user-supplied template content into PHP code and executes it via eval() without sanitization… | |
| Modified | High (8.8) | 0.17% | — | Servit Affiliate-toolkit | 4/22/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit affiliate-toolkit-starter allows Cross Site Request Forgery.This issue affects affiliate-toolkit: from n/a through <= 3.7.3. | |
| Deferred | Medium (6.1) | 0.45% | — | Servit Affiliate-toolkitAI | 11/21/2024 | 6/17/2026 | The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Deferred | Medium (6.4) | 0.34% | — | Affiliate-toolkit Affiliate ToolkitAI | 10/29/2024 | 6/17/2026 | The affiliate-toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's atkp_product shortcode in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Deferred | Medium (5.3) | 0.59% | — | Servit Affiliate-toolkitAI | 8/12/2024 | 6/17/2026 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is due display_errors being set to true . This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be… | |
| Deferred | Medium (5.3) | 0.44% | — | Servit Affiliate-toolkitAI | 7/10/2024 | 6/17/2026 | Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4. | |
| Deferred | Medium (6.5) | 0.34% | — | Servit Affiliate-toolkitAI | 3/27/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit allows Stored XSS.This issue affects affiliate-toolkit: from n/a through 3.4.5. | |
| Modified | Medium (4.3) | 0.32% | — | Servit Affiliate-toolkit | 3/8/2024 | 6/17/2026 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modified | Medium (6.5) | 0.29% | — | Servit Affiliate-toolkit | 3/8/2024 | 6/17/2026 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modified | Critical (9.8) | 0.90% | — | Servit Affiliate-toolkit | 1/1/2024 | 6/17/2026 | The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private addresses, leading to a Server Side Request… | |
| Modified | Medium (6.1) | 0.41% | — | Servit Affiliate-toolkit | 12/19/2023 | 6/17/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.3.9. | |
| Modified | Medium (6.1) | 0.41% | — | Servit Affiliate-toolkit | 11/30/2023 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SERVIT Software Solutions affiliate-toolkit – WordPress Affiliate Plugin allows Reflected XSS.This issue affects affiliate-toolkit – WordPress Affiliate Plugin: from n/a through 3.4.3. | |
| Modified | Medium (5.4) | 0.36% | — | Servit Affiliate-toolkit | 5/10/2023 | 6/17/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Christof Servit affiliate-toolkit plugin <= 3.3.3 versions. |