Vulnerabilities
Summary — last 7 days
New vulnerabilities2,834▲ 81 vs. last week
Critical / high1,316▼ 206 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.1) | 0.25% | — | Video Background BlockAI | 10/6/2026 | 10/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions. | |
| Deferred | High (8.8) | 0.51% | — | Slider Hero With Video Background AnimationAI | 8/22/2026 | 8/26/2026 | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an… | |
| Deferred | High (7.1) | 0.22% | — | Lambertgroup Countdown With Image OR Video BackgroundAI | 1/8/2026 | 10/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup CountDown With Image or Video Background countdown-with-background allows Reflected XSS.This issue affects CountDown With Image or Video Background: from n/a through <= 1.5. | |
| Modified | Medium (5.4) | 0.53% | — | Pushlabs Video Background | 3/13/2023 | 6/17/2026 | The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks |