Vulnerabilities
Summary — last 7 days
New vulnerabilities2,712▼ 359 vs. last week
Critical / high1,261▼ 231 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)213▼ 109 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.9) | 0.36% | — | Vibethemes BP Social ConnectAI | 4/9/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes BP Social Connect bp-social-connect allows Stored XSS.This issue affects BP Social Connect: from n/a through <= 1.6.2. | |
| Deferred | High (7.1) | 0.19% | — | Ninotheme Nino Social ConnectAI | 4/9/2025 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ninotheme Nino Social Connect nino-social-connect allows Stored XSS.This issue affects Nino Social Connect: from n/a through <= 2.0. | |
| Deferred | High (7.1) | 0.20% | — | Z.com BY GMO GMO Social ConnectionAI | 11/19/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Z.com byGMO GMO Social Connection gmo-social-connection allows Cross-Site Scripting (XSS).This issue affects GMO Social Connection: from n/a through <= 1.2. | |
| Deferred | Critical (9.8) | 0.79% | — | Social ConnectAI | 5/8/2024 | 6/17/2026 | The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. This is due to insufficient verification on the OpenID server being supplied during the social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing… | |
| Modified | Critical (9.8) | 1.6% | — | Vibethemes BP Social Connect | 5/19/2023 | 6/17/2026 | The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Modified | Medium (4.3) | 1.6% | — | Social Connect Project Social Connect | 7/2/2014 | 6/17/2026 | Cross-site scripting (XSS) vulnerability in diagnostics/test.php in the Social Connect plugin 1.0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the testing parameter. |