Vulnerabilities
Summary — last 7 days
New vulnerabilities2,759▼ 357 vs. last week
Critical / high1,278▼ 254 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)223▼ 98 vs. last week
2 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 0.49% | — | Wplite Wp-lister Lite FOR Amazon | 1/2/2023 | 6/17/2026 | The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin. | |
| Modified | Medium (6.5) | 0.41% | — | Wplite Project Wplite | 6/20/2022 | 6/17/2026 | The WPlite WordPress plugin through 1.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |