Vulnerabilities
Summary — last 7 days
New vulnerabilities2,716▼ 25 vs. last week
Critical / high1,269▼ 244 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
1,860 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.1) | — | — | Fuelthemes THE VouxAI | 10/9/2026 | 10/9/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5. | |
| Deferred | High (8.8) | — | — | Buddhathemes NEO Barber ShopAI | 10/9/2026 | 10/9/2026 | Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5. | |
| Deferred | High (8.1) | — | — | Fuelthemes WerkstattAI | 10/9/2026 | 10/9/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through 4.8.3. | |
| Deferred | High (7.1) | — | — | Designthemes Whistle Sports ClubAI | 10/9/2026 | 10/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Whistle - Sports Club: from n/a through 4.2. | |
| Deferred | Critical (9.3) | — | — | Vibethemes WplmsAI | 10/9/2026 | 10/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2. | |
| Deferred | High (8.5) | — | — | Vibethemes WplmsAI | 10/9/2026 | 10/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973. | |
| Deferred | High (7.1) | — | — | Extendthemes KubioAI | 10/9/2026 | 10/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3. | |
| Deferred | Medium (6.5) | 0.25% | — | Bdthemes Ultimate Post KITAI | 10/8/2026 | 10/8/2026 | Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5. | |
| Deferred | Medium (5.3) | 0.18% | — | Yithemes Yith Woocommerce Product BundlesAI | 10/8/2026 | 10/8/2026 | Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0. | |
| Deferred | Medium (6.5) | 0.16% | — | Stylemixthemes Masterstudy LMSAI | 10/8/2026 | 10/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes MasterStudy LMS masterstudy-lms-learning-management-system allows Stored XSS.This issue affects MasterStudy LMS: from n/a through 3.7.52. | |
| Deferred | High (7.6) | 0.23% | — | Afthemes WP Post AuthorAI | 10/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Author: from n/a through 4.0.0. | |
| Deferred | Medium (6.5) | 0.21% | — | Bdthemes Prime SliderAI | 10/7/2026 | 10/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2. | |
| Deferred | Medium (6.5) | 0.21% | — | Bdthemes Element PackAI | 10/7/2026 | 10/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6. | |
| Deferred | Medium (6.5) | 0.21% | — | Bdthemes Element PackAI | 10/7/2026 | 10/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6. | |
| Rejected | Unscored | 0.74% | — | Elegantthemes DiviAI | 10/6/2026 | 10/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-1829. | |
| Deferred | Medium (6.9) | 0.41% | — | Stylemixthemes MotorsAI | 10/6/2026 | 10/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. | |
| Deferred | Medium (6.9) | 0.27% | — | Cozythemes Cozy BlocksAI | 10/5/2026 | 10/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23. | |
| Deferred | High (7.5) | 0.24% | — | Stylemixthemes Cost Calculator BuilderAI | 10/4/2026 | 10/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17. | |
| Deferred | Medium (6.5) | 0.21% | — | Creativethemes Blocksy CompanionAI | 9/30/2026 | 9/30/2026 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. | |
| Deferred | High (7.1) | 0.18% | — | Yithemes Yith Woocommerce Ajax SearchAI | 9/30/2026 | 9/30/2026 | Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions. | |
| Deferred | Medium (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 9/30/2026 | 9/30/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Deferred | Medium (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 9/30/2026 | 9/30/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Deferred | Medium (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 9/30/2026 | 9/30/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for… | |
| Deferred | Medium (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 9/30/2026 | 9/30/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for… | |
| Deferred | Medium (6.4) | 0.16% | — | Bold-themes Bold Page BuilderAI | 9/30/2026 | 9/30/2026 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… |