Vulnerabilities
Summary — last 7 days
New vulnerabilities2,759▼ 357 vs. last week
Critical / high1,278▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.21% | — | Codefish Pinterest Pinboard WidgetAI | 9/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7. | |
| Modified | Medium (5.4) | 0.51% | — | AS - Create Pinterest Pinboard Pages Project AS - Create Pinterest Pinboard Pages | 8/23/2022 | 6/17/2026 | Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress. | |
| Modified | Medium (5.4) | 0.83% | — | Pinboard Project Pinboard | 1/27/2020 | 6/16/2026 | Pinboard 1.0.6 theme for Wordpress has XSS. | |
| Modified | Critical (9.8) | 2.7% | 💥 Exploit | Social Pinboard Project Social Pinboard | 2/17/2018 | 6/17/2026 | SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a… | |
| Modified | High (7.5) | 0.99% | 💥 Exploit | Pinme COM Pinboard | 7/27/2009 | 6/16/2026 | SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php. | |
| Modified | High (7.5) | 1.0% | — | Typo3 Pinboard Extension | 7/7/2008 | 6/16/2026 | SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modified | High (7.5) | 1.6% | — | Openpinboard | 1/4/2007 | 6/16/2026 | PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter. NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small… | |
| Modified | Medium (4.3) | 1.4% | — | Pinboard | 12/31/2002 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists. |