Vulnerabilities

Summary — last 7 days

New vulnerabilities2,757▲ 47 vs. last week
Critical / high1,482▲ 372 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

10 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.15%—Favethemes Houzez Theme FunctionalityAI1/22/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality allows Stored XSS.This issue affects Houzez Theme - Functionality: from n/a through <= 4.2.6.
DeferredMedium (4.3)0.22%—Portotheme Porto Theme FunctionalityAI12/9/20256/17/2026
Missing Authorization vulnerability in p-themes Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 3.7.3.
DeferredHigh (7.1)0.23%—Favethemes Houzez Theme FunctionalityAI11/6/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Houzez Theme - Functionality houzez-theme-functionality.This issue affects Houzez Theme - Functionality: from n/a through < 4.2.0.
DeferredMedium (5.3)0.38%—Portotheme Porto Theme FunctionalityAI1/2/20256/17/2026
Missing Authorization vulnerability in Porto Theme Porto Theme - Functionality porto-functionality allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Porto Theme - Functionality: from n/a through < 2.12.1.
AnalyzedMedium (5.3)0.40%—Code-projects Simple Crud Functionality12/5/20246/17/2026
A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The manipulation of the argument newtitle/newdescr leads to cross site scripting. The attack can be initiated remotely. The exploit has been…
DeferredHigh (8.8)0.45%—Houzez Theme FunctionalityAI7/9/20246/17/2026
The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
DeferredHigh (8.8)1.0%—Porto Theme FunctionalityAI5/14/20246/17/2026
The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the…
DeferredHigh (8.8)1.0%—Porto Theme FunctionalityAI5/14/20246/17/2026
The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and…
ModifiedCritical (9.8)0.77%—Portotheme Functionality12/19/20236/17/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Porto Theme Porto Theme - Functionality.This issue affects Porto Theme - Functionality: from n/a before 2.12.1.
ModifiedCritical (9.8)0.78%—Code-projects Simple Crud Functionality11/17/20236/17/2026
SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.