Vulnerabilities

Summary — last 7 days

New vulnerabilities2,759▼ 357 vs. last week
Critical / high1,278▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.21%—Codefish Pinterest Pinboard WidgetAI9/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7.
ModifiedMedium (5.4)0.51%—AS - Create Pinterest Pinboard Pages Project AS - Create Pinterest Pinboard Pages8/23/20226/17/2026
Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress.
ModifiedMedium (5.4)0.83%—Pinboard Project Pinboard1/27/20206/16/2026
Pinboard 1.0.6 theme for Wordpress has XSS.
ModifiedCritical (9.8)2.7%💥 ExploitSocial Pinboard Project Social Pinboard2/17/20186/17/2026
SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a…
ModifiedHigh (7.5)0.99%💥 ExploitPinme COM Pinboard7/27/20096/16/2026
SQL injection vulnerability in the com_pinboard component for Joomla! allows remote attackers to execute arbitrary SQL commands via the task parameter in a showpic action to index.php.
ModifiedHigh (7.5)1.0%—Typo3 Pinboard Extension7/7/20086/16/2026
SQL injection vulnerability in the Pinboard extension 0.0.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModifiedHigh (7.5)1.6%—Openpinboard1/4/20076/16/2026
PHP remote file inclusion vulnerability in index.php in OpenPinboard 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the language parameter. NOTE: this issue has been disputed by the developer and a third party, since the variable is set before use. CVE analysis suggests that there is a small…
ModifiedMedium (4.3)1.4%—Pinboard12/31/20026/16/2026
Cross-site scripting (XSS) vulnerability in Pinboard 1.0 allows remote attackers to inject arbitrary web script or HTML via tasklists.
Orbitaley — Vulnerabilities