Vulnerabilities

Summary — last 7 days

New vulnerabilities3,040▲ 560 vs. last week
Critical / high1,452▲ 279 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)382▲ 175 vs. last week
–

186 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.2)——AutoptimizeAI10/1/202610/1/2026
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
DeferredMedium (4.9)0.22%—Shortpixel Image OptimizerAI9/30/20269/30/2026
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
DeferredMedium (6.5)0.22%—Ewww Image OptimizerAI9/30/20269/30/2026
Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.
DeferredMedium (4.4)0.17%—Ewww Image OptimizerAI9/30/20269/30/2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an attacker with Administrator-level access rename or delete existing WebP-derivative image files outside that scope, including, on a multisite network,…
DeferredMedium (6.6)0.35%—Ewww Image OptimizerAI9/30/20269/30/2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta field that is deserialized when the post is rendered, allowing them to perform PHP Object Injection, which can lead to remote code execution when a…
DeferredMedium (4.3)0.18%—Image OptimizerAI9/30/20269/30/2026
The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user to read attachment metadata and site-wide statistics that should be restricted to administrators.
DeferredHigh (7.5)0.22%—Robin Image OptimizerAI9/30/20269/30/2026
The Robin Image Optimizer WordPress plugin before 2.0.8 does not escape values that its bundled HTML parser re-emits into element attributes when a non-default image delivery mode is enabled, allowing unauthenticated users to submit content that is stored and later executed as Cross-Site Scripting in the browser of…
DeferredMedium (4.3)0.16%—Robin Image OptimizerAI9/30/20269/30/2026
The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing users with a subscriber-level account to render admin-only Robin Image Optimizer WordPress plugin before 2.0.8 pages and disclose the Robin…
DeferredHigh (8.4)0.70%—Token Optimizer MCPAI9/28/202610/1/2026
Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, token-optimizer-mcp is vulnerable to OS command injection in the smart_user tool. Any MCP client that can call the smart_user tool can execute…
DeferredMedium (5.3)0.45%—Token Optimizer MCPAI9/28/20269/30/2026
Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge graph across 16 CLI clients. Prior to version 5.1.0, the dashboard HTTP server in token-optimizer-mcp exposes /api/session-summary and /api/session-events with no authentication middleware — any…
Awaiting AnalysisMedium (6.8)0.15%—Dell Boot Optimized Server StorageAI9/28/20269/28/2026
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to…
DeferredMedium (4.9)0.51%—WP OptimizerAI9/19/20269/21/2026
The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to and including 2.5.0. This is due to an unsafe subquery-detection branch in the Query::parse_key_compare_field() method that, when the user-supplied value matches the regex ^[(\s]*SELECT\s+, wraps the value…
DeferredHigh (8.8)0.89%—Shortpixel Image OptimizerAI9/18/20269/18/2026
The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible for authenticated attackers, with author-level access and above, to inject a PHP…
DeferredMedium (6.8)0.43%—Ewww Image OptimizerAI9/17/20269/18/2026
The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views…
DeferredMedium (5.9)0.36%—SVG OptimizerAI9/14/20269/22/2026
The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.
DeferredHigh (8)0.41%—Qodeinteractive OptimizeAI9/5/20269/8/2026
The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a…
DeferredLow (2.7)0.26%—Qodeinteractive OptimizeAI9/5/20269/8/2026
The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names…
DeferredHigh (7.2)0.28%—Ewww Image OptimizerAI9/3/20269/3/2026
Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.
DeferredHigh (8.6)3.2%—Redport Optimizer Wxa-203AIRedport Optimizer Wxa-213AIRedport Optimizer Wxa-223AI8/31/20269/1/2026
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The…
DeferredMedium (6.4)0.42%—Ewww Image OptimizerAI8/19/20268/20/2026
The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in all versions up to, and including, 8.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
DeferredMedium (6.4)0.41%—Siteground Speed OptimizerAI8/19/20268/20/2026
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attributes in all versions up to, and including, 7.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
DeferredMedium (6.1)0.27%—LWS OptimizeAI8/9/20268/26/2026
The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the…
DeferredMedium (5.3)0.35%—Siteground Security OptimizerAI8/6/20268/26/2026
The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control…
DeferredMedium (4.3)0.33%—LWS OptimizeAI8/2/20268/26/2026
The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.
DeferredHigh (8.1)0.66%—Image OptimizerAI7/2/20267/2/2026
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they…