Vulnerabilities

Summary — last 7 days

New vulnerabilities2,834▲ 81 vs. last week
Critical / high1,316▼ 206 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.25%—Video Background BlockAI10/6/202610/6/2026
Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.
DeferredHigh (8.8)0.51%—Slider Hero With Video Background AnimationAI8/22/20268/26/2026
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an…
DeferredHigh (7.1)0.22%—Lambertgroup Countdown With Image OR Video BackgroundAI1/8/202610/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup CountDown With Image or Video Background countdown-with-background allows Reflected XSS.This issue affects CountDown With Image or Video Background: from n/a through <= 1.5.
ModifiedMedium (5.4)0.53%—Pushlabs Video Background3/13/20236/17/2026
The Video Background WordPress plugin before 2.7.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Orbitaley — Vulnerabilities