Vulnerabilities

Summary — last 7 days

New vulnerabilities2,712▼ 359 vs. last week
Critical / high1,261▼ 231 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)213▼ 109 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.9)0.36%—Vibethemes BP Social ConnectAI4/9/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes BP Social Connect bp-social-connect allows Stored XSS.This issue affects BP Social Connect: from n/a through <= 1.6.2.
DeferredHigh (7.1)0.19%—Ninotheme Nino Social ConnectAI4/9/20256/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect nino-social-connect allows Stored XSS.This issue affects Nino Social Connect: from n/a through <= 2.0.
DeferredHigh (7.1)0.20%—Z.com BY GMO GMO Social ConnectionAI11/19/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Z.com byGMO GMO Social Connection gmo-social-connection allows Cross-Site Scripting (XSS).This issue affects GMO Social Connection: from n/a through <= 1.2.
DeferredCritical (9.8)0.79%—Social ConnectAI5/8/20246/17/2026
The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing…
ModifiedCritical (9.8)1.6%—Vibethemes BP Social Connect5/19/20236/17/2026
The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on…
ModifiedMedium (4.3)1.6%—Social Connect Project Social Connect7/2/20146/17/2026
Cross-site scripting (XSS) vulnerability in diagnostics/test.php in the Social Connect plugin 1.0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the testing parameter.