Vulnerabilities

Summary — last 7 days

New vulnerabilities2,716▼ 25 vs. last week
Critical / high1,269▼ 244 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

1,860 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.1)——Fuelthemes THE VouxAI10/9/202610/9/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.
DeferredHigh (8.8)——Buddhathemes NEO Barber ShopAI10/9/202610/9/2026
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
DeferredHigh (8.1)——Fuelthemes WerkstattAI10/9/202610/9/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through 4.8.3.
DeferredHigh (7.1)——Designthemes Whistle Sports ClubAI10/9/202610/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Whistle - Sports Club: from n/a through 4.2.
DeferredCritical (9.3)——Vibethemes WplmsAI10/9/202610/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2.
DeferredHigh (8.5)——Vibethemes WplmsAI10/9/202610/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973.
DeferredHigh (7.1)——Extendthemes KubioAI10/9/202610/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3.
DeferredMedium (6.5)0.25%—Bdthemes Ultimate Post KITAI10/8/202610/8/2026
Missing Authorization vulnerability in BdThemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Post Kit: from n/a through 4.5.5.
DeferredMedium (5.3)0.18%—Yithemes Yith Woocommerce Product BundlesAI10/8/202610/8/2026
Missing Authorization vulnerability in YITH YITH WooCommerce Product Bundles yith-woocommerce-product-bundles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YITH WooCommerce Product Bundles: from n/a through 2.29.0.
DeferredMedium (6.5)0.16%—Stylemixthemes Masterstudy LMSAI10/8/202610/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes MasterStudy LMS masterstudy-lms-learning-management-system allows Stored XSS.This issue affects MasterStudy LMS: from n/a through 3.7.52.
DeferredHigh (7.6)0.23%—Afthemes WP Post AuthorAI10/7/202610/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Blind SQL Injection.This issue affects WP Post Author: from n/a through 4.0.0.
DeferredMedium (6.5)0.21%—Bdthemes Prime SliderAI10/7/202610/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 4.6.2.
DeferredMedium (6.5)0.21%—Bdthemes Element PackAI10/7/202610/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6.
DeferredMedium (6.5)0.21%—Bdthemes Element PackAI10/7/202610/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack Elementor Addons: from n/a through 8.8.6.
RejectedUnscored0.74%—Elegantthemes DiviAI10/6/202610/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-1829.
DeferredMedium (6.9)0.41%—Stylemixthemes MotorsAI10/6/202610/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
DeferredMedium (6.9)0.27%—Cozythemes Cozy BlocksAI10/5/202610/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23.
DeferredHigh (7.5)0.24%—Stylemixthemes Cost Calculator BuilderAI10/4/202610/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from n/a through 4.0.17.
DeferredMedium (6.5)0.21%—Creativethemes Blocksy CompanionAI9/30/20269/30/2026
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
DeferredHigh (7.1)0.18%—Yithemes Yith Woocommerce Ajax SearchAI9/30/20269/30/2026
Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for…
DeferredMedium (6.4)0.16%—Bold-themes Bold Page BuilderAI9/30/20269/30/2026
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
Orbitaley — Vulnerabilities