Vulnerabilities
Summary — last 7 days
New vulnerabilities2,823▼ 249 vs. last week
Critical / high1,318▼ 180 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
143 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.3) | 0.22% | — | WP Hosting AS PAY With Vipps FOR WoocommerceAI | 9/30/2026 | 9/30/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Hosting AS Pay with Vipps for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.4. | |
| Deferred | High (7.5) | 0.29% | — | Hostinger MigratorAI | 9/30/2026 | 9/30/2026 | Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | |
| Deferred | Medium (6.8) | 0.24% | — | Hostinger ReachAI | 9/30/2026 | 9/30/2026 | The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content… | |
| Deferred | High (8.8) | 0.43% | — | Ankara Hosting Site Management PanelAI | 8/31/2026 | 9/1/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects Site Management Panel: through 15062026. | |
| Deferred | Medium (5.3) | 0.38% | — | Hostinger ReachAI | 5/13/2026 | 6/17/2026 | The Hostinger Reach – AI-Powered Email Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_ajax_action' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with… | |
| Analyzed | Critical (9.3) | 0.61% | — | Codefuture Image Hosting Script | 4/12/2026 | 6/17/2026 | CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter. | |
| Deferred | High (7.1) | 0.18% | — | Whmc Sdes Phox HostingAI | 3/25/2026 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a through <= 2.0.8. | |
| Deferred | Medium (6.9) | 0.29% | — | Yetishare File Hosting ScriptAI | 1/23/2026 | 6/17/2026 | YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:///… | |
| Analyzed | Medium (6.1) | 0.29% | — | Ehcp Easy Hosting Control Panel | 8/22/2025 | 6/17/2026 | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter. | |
| Analyzed | Medium (6.1) | 0.24% | — | Ehcp Easy Hosting Control Panel | 8/22/2025 | 6/17/2026 | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter. | |
| Modified | Medium (5.4) | 0.23% | — | Ehcp Easy Hosting Control Panel | 8/21/2025 | 6/17/2026 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter. | |
| Analyzed | Medium (6.5) | 0.26% | — | Ehcp Easy Hosting Control Panel | 8/19/2025 | 6/17/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. | |
| Analyzed | Medium (4.8) | 0.24% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 6/17/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function. | |
| Analyzed | Medium (6.3) | 0.20% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 6/17/2026 | A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter. | |
| Deferred | High (7.1) | 0.21% | — | Ezihosting Tennis Court BookingsAI | 7/16/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EZiHosting Tennis Court Bookings tennis-court-bookings allows Reflected XSS.This issue affects Tennis Court Bookings: from n/a through <= 1.2.7. | |
| Deferred | Medium (4.3) | 0.17% | — | Hosting.io JPG PNG Compression AND OptimizationAI | 2/24/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hosting.io JPG, PNG Compression and Optimization wp-image-compression allows Cross Site Request Forgery.This issue affects JPG, PNG Compression and Optimization: from n/a through <= 1.7.35. | |
| Deferred | High (7.1) | 0.32% | — | Scott Farrell WP Hosting Performance CheckAI | 1/9/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp Hosting Performance Check wp-hosting-performance-check allows Reflected XSS.This issue affects wp Hosting Performance Check: from n/a through <= 2.18.8. | |
| Deferred | High (7.1) | 0.21% | — | Hosting IO WP ControllerAI | 12/16/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hosting.io WP Controller wp-management-controller allows Stored XSS.This issue affects WP Controller: from n/a through <= 3.2.0. | |
| Deferred | Medium (4.3) | 0.20% | — | Anton Aleksandrov Wordpress Hosting Benchmark ToolAI | 4/15/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6. | |
| Modified | Medium (5.4) | 0.31% | — | Wp-hosting PAY With Vipps AND Mobilepay FOR Woocommerce | 2/10/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Hosting Pay with Vipps and MobilePay for WooCommerce allows Stored XSS.This issue affects Pay with Vipps and MobilePay for WooCommerce: from n/a through 1.14.13. | |
| Modified | Medium (6.5) | 0.45% | — | Hostinger | 1/11/2024 | 6/17/2026 | The Hostinger plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the function publish_website in all versions up to, and including, 1.9.7. This makes it possible for unauthenticated attackers to enable and disable maintenance mode. | |
| Modified | Medium (4.3) | 0.23% | — | A2hosting A2 Optimized | 3/13/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A2 Hosting A2 Optimized WP plugin <= 3.0.4 versions. | |
| Modified | Medium (6.1) | 0.74% | — | Webhostings WH Testimonials | 3/13/2023 | 6/17/2026 | The WH Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as wh_homepage, wh_text_short, wh_text_full and in versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modified | Medium (6.1) | 0.99% | — | Simbahosting Two-factor-authentication | 8/28/2019 | 6/17/2026 | The two-factor-authentication plugin before 1.1.10 for WordPress has XSS in the admin area. | |
| Modified | High (7.5) | 8.8% | 💥 Exploit | Hostingcontroller Hc10 | 6/24/2019 | 6/17/2026 | The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. |