Vulnerabilities

Summary — last 7 days

New vulnerabilities2,517▼ 423 vs. last week
Critical / high1,296▲ 12 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)57▼ 471 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.4)0.26%—Xylusthemes WP Event AggregatorAI2/18/20266/17/2026
The WP Event Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_events' shortcode in all versions up to, and including, 1.8.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModifiedMedium (6.1)0.26%—Xylusthemes WP Event Aggregator2/14/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator wp-event-aggregator allows Reflected XSS.This issue affects WP Event Aggregator: from n/a through <= 1.8.2.
AnalyzedMedium (6.5)0.27%—Xylusthemes WP Event Aggregator7/20/20246/17/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xylus Themes WP Event Aggregator allows Stored XSS.This issue affects WP Event Aggregator: from n/a through 1.7.9.
ModifiedMedium (4.3)0.20%—Xylusthemes WP Event Aggregator4/12/20246/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in Xylus Themes WP Event Aggregator.This issue affects WP Event Aggregator: from n/a through 1.7.6.