Vulnerabilities
Summary — last 7 days
New vulnerabilities2,701▼ 534 vs. last week
Critical / high1,293▼ 229 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)215▼ 224 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 1.6% | — | Fast Secure Contact Form Project Fast Secure Contact Form | 11/26/2019 | 6/17/2026 | The Fast Secure Contact Form plugin before 4.0.38 for WordPress allows fs_contact_form1[welcome] XSS. | |
| Modified | Medium (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 12/20/2017 | 6/17/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… |