Vulnerabilities
Summary — last 7 days
New vulnerabilities3,338▲ 363 vs. last week
Critical / high1,493▲ 135 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 119 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.8) | 0.41% | — | Afrfq Request A Quote FOR WoocommerceAI | 9/26/2026 | 9/28/2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied… | |
| Deferred | Critical (9.8) | 0.48% | — | Yith Request A Quote FOR WoocommerceAI | 9/3/2026 | 9/7/2026 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. | |
| Deferred | High (7.3) | 0.76% | — | Request A Quote FOR Woocommerce AND ElementorAI | 11/23/2024 | 6/17/2026 | The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation plugin for WordPress is vulnerable to arbitrary shortcode execution via fire_contact_form AJAX action in all versions up to, and including, 1.4. This is due to the software allowing users to… |