Vulnerabilities

Summary — last 7 days

New vulnerabilities2,747▼ 495 vs. last week
Critical / high1,308▼ 202 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)225▼ 276 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.1)0.37%—WP Contact Form 7 DB HandlerAI5/28/20266/17/2026
The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only…
DeferredHigh (7.1)0.39%—Kkwangen WP Contact Form IIIAI3/26/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KKWangen WP Contact Form III wp-contact-form-iii allows Reflected XSS.This issue affects WP Contact Form III: from n/a through <= 1.6.2d.
ModifiedHigh (8.8)0.23%—Ftwr WP Contact Form2/12/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ryan Duff, Peter Westwood WP Contact Form.This issue affects WP Contact Form: from n/a through 1.6.
ModifiedMedium (4.8)0.37%—Enhanced WP Contact Form Project Enhanced WP Contact Form5/10/20236/17/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions.
Orbitaley — Vulnerabilities