Vulnerabilities
Summary — last 7 days
New vulnerabilities2,597▼ 310 vs. last week
Critical / high1,338▲ 74 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)64▼ 463 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Received | Medium (6.5) | 0.16% | — | Brainstormforce Presto PlayerAI | 10/5/2026 | 10/5/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2. | |
| Deferred | Medium (6.4) | 0.42% | — | Prestoplayer Presto PlayerAI | 6/12/2026 | 8/28/2026 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url… | |
| Deferred | Medium (4.3) | 0.27% | — | Brainstormforce Presto PlayerAI | 5/19/2026 | 6/17/2026 | Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3. | |
| Deferred | Medium (6.3) | 0.39% | — | Prestoplayer Presto PlayerAI | 11/1/2024 | 6/17/2026 | Missing Authorization vulnerability in Presto Made, Inc Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Presto Player: from n/a through 3.0.2. | |
| Analyzed | Medium (4.7) | 0.50% | — | Prestoplayer Presto Player | 4/10/2024 | 6/17/2026 | The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS… |