Vulnerabilities
Summary — last 7 days
New vulnerabilities2,709▼ 126 vs. last week
Critical / high1,231▼ 312 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)257▲ 221 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.28% | — | Mark Odonnell Mstw CSV ExporterAI | 10/27/2025 | 10/8/2026 | Missing Authorization vulnerability in Mark O'Donnell MSTW CSV EXPORTER mstw-csv-exporter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MSTW CSV EXPORTER: from n/a through <= 1.4. | |
| Modified | High (8.8) | 0.60% | — | Kigurumi CSV Exporter | 11/7/2023 | 6/17/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Nakashima Masahiro WP CSV Exporter.This issue affects WP CSV Exporter: from n/a through 2.0. | |
| Modified | High (7.8) | 0.42% | — | WP CSV Exporter Project WP CSV Exporter | 12/12/2022 | 6/17/2026 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability. | |
| Modified | High (7.2) | 1.0% | — | WP CSV Exporter Project WP CSV Exporter | 12/5/2022 | 6/17/2026 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks |