Vulnerabilities

Summary — last 7 days

New vulnerabilities2,823▼ 249 vs. last week
Critical / high1,318▼ 180 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

143 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.3)0.22%—WP Hosting AS PAY With Vipps FOR WoocommerceAI9/30/20269/30/2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4.
DeferredHigh (7.5)0.29%—Hostinger MigratorAI9/30/20269/30/2026
Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.
DeferredMedium (6.8)0.24%—Hostinger ReachAI9/30/20269/30/2026
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content…
DeferredHigh (8.8)0.43%—Ankara Hosting Site Management PanelAI8/31/20269/1/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026.
DeferredMedium (5.3)0.38%—Hostinger ReachAI5/13/20266/17/2026
The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with…
AnalyzedCritical (9.3)0.61%—Codefuture Image Hosting Script4/12/20266/17/2026
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
DeferredHigh (7.1)0.18%—Whmc Sdes Phox HostingAI3/25/20266/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a through <= 2.0.8.
DeferredMedium (6.9)0.29%—Yetishare File Hosting ScriptAI1/23/20266/17/2026
YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:///…
AnalyzedMedium (6.1)0.29%—Ehcp Easy Hosting Control Panel8/22/20256/17/2026
Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter.
AnalyzedMedium (6.1)0.24%—Ehcp Easy Hosting Control Panel8/22/20256/17/2026
Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter.
ModifiedMedium (5.4)0.23%—Ehcp Easy Hosting Control Panel8/21/20256/17/2026
SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter.
AnalyzedMedium (6.5)0.26%—Ehcp Easy Hosting Control Panel8/19/20256/17/2026
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.
AnalyzedMedium (4.8)0.24%—Ehcp Easy Hosting Control Panel8/8/20256/17/2026
Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.
AnalyzedMedium (6.3)0.20%—Ehcp Easy Hosting Control Panel8/8/20256/17/2026
A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter.
DeferredHigh (7.1)0.21%—Ezihosting Tennis Court BookingsAI7/16/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EZiHosting Tennis Court Bookings tennis-court-bookings allows Reflected XSS.This issue affects Tennis Court Bookings: from n/a through <= 1.2.7.
DeferredMedium (4.3)0.17%—Hosting.io JPG PNG Compression AND OptimizationAI2/24/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in hosting.io JPG, PNG Compression and Optimization wp-image-compression allows Cross Site Request Forgery.This issue affects JPG, PNG Compression and Optimization: from n/a through <= 1.7.35.
DeferredHigh (7.1)0.32%—Scott Farrell WP Hosting Performance CheckAI1/9/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8.
DeferredHigh (7.1)0.21%—Hosting IO WP ControllerAI12/16/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in hosting.io WP Controller wp-management-controller allows Stored XSS.This issue affects WP Controller: from n/a through <= 3.2.0.
DeferredMedium (4.3)0.20%—Anton Aleksandrov Wordpress Hosting Benchmark ToolAI4/15/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6.
ModifiedMedium (5.4)0.31%—Wp-hosting PAY With Vipps AND Mobilepay FOR Woocommerce2/10/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hosting Pay with Vipps and MobilePay for WooCommerce allows Stored XSS.This issue affects Pay with Vipps and MobilePay for WooCommerce: from n/a through 1.14.13.
ModifiedMedium (6.5)0.45%—Hostinger1/11/20246/17/2026
The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode.
ModifiedMedium (4.3)0.23%—A2hosting A2 Optimized3/13/20236/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in A2 Hosting A2 Optimized WP plugin <= 3.0.4 versions.
ModifiedMedium (6.1)0.74%—Webhostings WH Testimonials3/13/20236/17/2026
The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
ModifiedMedium (6.1)0.99%—Simbahosting Two-factor-authentication8/28/20196/17/2026
The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area.
ModifiedHigh (7.5)8.8%💥 ExploitHostingcontroller Hc106/24/20196/17/2026
The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS.