Vulnerabilities
Summary — last 7 days
New vulnerabilities2,747▼ 495 vs. last week
Critical / high1,308▼ 202 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.1) | 0.37% | — | WP Contact Form 7 DB HandlerAI | 5/28/2026 | 6/17/2026 | The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only… | |
| Deferred | High (7.1) | 0.39% | — | Kkwangen WP Contact Form IIIAI | 3/26/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KKWangen WP Contact Form III wp-contact-form-iii allows Reflected XSS.This issue affects WP Contact Form III: from n/a through <= 1.6.2d. | |
| Modified | High (8.8) | 0.23% | — | Ftwr WP Contact Form | 2/12/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6. | |
| Modified | Medium (4.8) | 0.37% | — | Enhanced WP Contact Form Project Enhanced WP Contact Form | 5/10/2023 | 6/17/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions. |