Vulnerabilities
Summary — last 7 days
New vulnerabilities2,739▲ 36 vs. last week
Critical / high1,474▲ 366 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)62▼ 464 vs. last week
153 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Undergoing Analysis | Critical (10) | 0.46% | — | Joomcode JctablesAI | 9/30/2026 | 9/30/2026 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated… | |
| Deferred | High (8.5) | 0.26% | — | Fatcatapps Easy Pricing TablesAI | 9/30/2026 | 9/30/2026 | Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | |
| Deferred | Medium (5.6) | 0.17% | — | Wpmanageninja Ninja TablesAI | 9/23/2026 | 9/23/2026 | The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry. | |
| Deferred | Medium (4.3) | 0.14% | — | Active Woot Products Tables FOR WoocommerceAI | 9/17/2026 | 9/18/2026 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products. | |
| Deferred | Medium (5.3) | 0.26% | — | DatatablesAIWwbn AvideoAI | 9/16/2026 | 9/22/2026 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings… | |
| Deferred | High (7.1) | 0.25% | — | WpdatatablesAI | 8/20/2026 | 8/20/2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. | |
| Deferred | Critical (9.3) | 0.65% | — | Ninja Tables PROAI | 8/13/2026 | 9/9/2026 | Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent… | |
| Deferred | Critical (9.3) | 0.40% | — | Active Products TablesAI | 8/13/2026 | 8/14/2026 | Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. | |
| Deferred | Critical (9.3) | 0.40% | — | Essekia Tablesome TableAI | 8/12/2026 | 8/12/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9. | |
| Deferred | High (7.1) | 0.25% | — | WpdatatablesAI | 8/6/2026 | 8/12/2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | |
| Deferred | High (7.1) | 0.25% | — | Wpmanageninja Ninja TablesAI | 8/6/2026 | 8/12/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | |
| Deferred | Low (2.1) | 0.23% | — | RacktablesAI | 8/4/2026 | 8/12/2026 | A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The… | |
| Deferred | High (7.5) | 0.44% | — | Pauple TablesomeAI | 7/28/2026 | 7/28/2026 | The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages. | |
| Deferred | Medium (5.3) | 0.33% | — | Wpmanageninja Ninja TablesAI | 7/23/2026 | 7/23/2026 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | |
| Deferred | High (7.1) | 0.25% | — | Pluginus Active Products Tables FOR WoocommerceAI | 7/13/2026 | 7/13/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0. | |
| Deferred | Medium (6.4) | 0.26% | — | Buddyholis TablesearchAI | 7/10/2026 | 7/10/2026 | The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Deferred | High (7.1) | 0.25% | — | WpdatatablesAI | 7/2/2026 | 7/2/2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions. | |
| Deferred | Critical (9.3) | 0.40% | — | WpdatatablesAI | 6/26/2026 | 6/26/2026 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. | |
| Deferred | Medium (6.5) | 0.30% | — | Filament ActionsAINextcloud TablesAI | 6/22/2026 | 6/23/2026 | Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and… | |
| Deferred | Critical (9.3) | 0.40% | — | WpdatatablesAI | 6/17/2026 | 6/17/2026 | Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. | |
| Analyzed | High (7.1) | 0.49% | — | Nextcloud Tables | 6/1/2026 | 7/22/2026 | Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the tables app to perform a limited SQL injection in the ORDER BY statement of a query. Compared to normal SQL injections,… | |
| Analyzed | High (8.2) | 0.52% | — | Nextcloud Tables | 6/1/2026 | 7/22/2026 | Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker with access to the Tables app may be able to execute arbitrary up to 20 bytes long SQL queries, through a stored… | |
| Analyzed | Medium (4.3) | 0.37% | — | Nextcloud Tables | 6/1/2026 | 7/22/2026 | Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. This issue has been patched in versions 1.0.4 and 2.0.0. | |
| Deferred | Critical (9.3) | 0.40% | — | Pluginus Active Products Tables FOR WoocommerceAI | 5/27/2026 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.9. | |
| Deferred | Critical (9.3) | 0.40% | — | Pluginus Active Products Tables FOR WoocommerceAI | 5/27/2026 | 6/17/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows Blind SQL Injection.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.8. |