Vulnerabilities
Summary — last 7 days
New vulnerabilities2,712▼ 359 vs. last week
Critical / high1,261▼ 231 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)213▼ 109 vs. last week
21 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.1) | 0.25% | — | Breadcrumb NavxtAI | 9/3/2026 | 9/3/2026 | Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions. | |
| Deferred | Medium (6.5) | 0.22% | — | Surbma Yoast SEO Breadcrumb ShortcodeAI | 7/2/2026 | 7/2/2026 | Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions. | |
| Deferred | Medium (4.3) | 0.19% | — | Genzel BreadcrumbsAI | 5/27/2026 | 6/17/2026 | The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the _options_page function. This makes it possible for unauthenticated attackers to update the plugin's breadcrumb configuration,… | |
| Deferred | Medium (5.3) | 0.34% | — | Breadcrumb NavxtAI | 2/19/2026 | 6/17/2026 | The Breadcrumb NavXT plugin for WordPress is vulnerable to authorization bypass through user-controlled key in versions up to and including 7.5.0. This is due to the Gutenberg block renderer trusting the $_REQUEST['post_id'] parameter without verification in the includes/blocks/build/breadcrumb-trail/render.php file.… | |
| Deferred | High (7.1) | 0.26% | — | Hung Trang SI SB BreadcrumbsAI | 7/4/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB Breadcrumbs sb-breadcrumbs allows Reflected XSS.This issue affects SB Breadcrumbs: from n/a through <= 1.0. | |
| Deferred | Medium (5.9) | 0.26% | — | Nitin Yawalkar Rdfa BreadcrumbAI | 6/20/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nitin Yawalkar RDFa Breadcrumb rdfa-breadcrumb allows Stored XSS.This issue affects RDFa Breadcrumb: from n/a through <= 2.3. | |
| Deferred | High (8.8) | 0.29% | — | Essential Marketer Essential BreadcrumbsAI | 4/9/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows Privilege Escalation.This issue affects Essential Breadcrumbs: from n/a through <= 1.1.1. | |
| Deferred | Medium (6.5) | 0.25% | — | Wikimedia Mediawiki Breadcrumbs2AI | 1/10/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.5, from… | |
| Deferred | High (7.1) | 0.16% | — | Essential Marketer Essential BreadcrumbsAI | 11/30/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows Stored XSS.This issue affects Essential Breadcrumbs: from n/a through <= 1.1.1. | |
| Modified | Medium (4.8) | 0.44% | — | Abhayrajmca Breadcrumb Simple | 8/30/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abhay Yadav Breadcrumb simple plugin <= 1.3 versions. | |
| Modified | Medium (5.4) | 0.59% | — | Pickplugins Breadcrumb | 2/6/2023 | 6/17/2026 | The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modified | Medium (4.8) | 0.59% | — | Very Simple Breadcrumb Project Very Simple Breadcrumb | 7/17/2022 | 6/17/2026 | The Very Simple Breadcrumb WordPress plugin through 1.0 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modified | Medium (6.1) | 3.6% | 💥 Exploit | Catchplugins Catch Breadcrumb | 4/23/2020 | 6/17/2026 | The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist and Alchemist PRO, Izabel and Izabel PRO, Chique and Chique PRO, Clean Enterprise and Clean Enterprise PRO, Bold… | |
| Modified | High (8.8) | 0.70% | — | Holest Breadcrumbs BY Menu | 9/3/2019 | 6/17/2026 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF. | |
| Modified | Medium (6.1) | 0.95% | — | Holest Breadcrumbs BY Menu | 9/3/2019 | 6/17/2026 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS. | |
| Modified | Low (2.1) | 0.74% | — | Path Breadcrumbs Project Path Breadcrumbs | 8/31/2015 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "Administer Path Breadcrumbs" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Medium (5) | 1.4% | — | Path Breadcrumbs Project Path Breadcrumbs | 4/21/2015 | 6/17/2026 | The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtain sensitive node titles by reading a 403 Not Found page. | |
| Modified | Medium (4.3) | 1.2% | — | Roger Padilla Camacho Easy Breadcrumb | 6/20/2014 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in the Easy Breadcrumb module 7.x-2.x before 7.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modified | Low (2.1) | 1.6% | — | Christopher Mitchell Smart Breadcrumb | 6/27/2012 | 6/16/2026 | The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter. | |
| Modified | Low (2.1) | 0.99% | — | Michael Nichols Taxonomy Breadcrumb | 5/19/2010 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 5.x before 5.x-1.5 and 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the taxonomy term name in a Breadcrumb display. | |
| Modified | Low (2.1) | 0.99% | — | Michael Nichols Taxonomy Breadcrumb | 5/19/2010 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb display. |