Vulnerabilities

Summary — last 7 days

New vulnerabilities2,597▼ 310 vs. last week
Critical / high1,338▲ 74 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)64▼ 463 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ReceivedMedium (6.5)0.16%—Brainstormforce Presto PlayerAI10/5/202610/5/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2.
DeferredMedium (6.4)0.42%—Prestoplayer Presto PlayerAI6/12/20268/28/2026
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url…
DeferredMedium (4.3)0.27%—Brainstormforce Presto PlayerAI5/19/20266/17/2026
Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3.
DeferredMedium (6.3)0.39%—Prestoplayer Presto PlayerAI11/1/20246/17/2026
Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Presto Player: from n/a through 3.0.2.
AnalyzedMedium (4.7)0.50%—Prestoplayer Presto Player4/10/20246/17/2026
The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS…