VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 363 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57814

WPMU DEV - Your All-in-One WordPress Platform Forminator

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows DOM-Based XSS.This issue affects Forminator: from n/a through <= 1.55.0.1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57813

properfraction MailOptin

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57811

Realtyna Realtyna Organic IDX plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57810

Saad Iqbal APIExperts Square for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExperts Square for WooCommerce woosquare allows Blind SQL Injection.This issue affects APIExperts Square for WooCommerce: from n/a through <= 4.7.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57805

Select-Themes Tonda

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Tonda tonda allows PHP Local File Inclusion.This issue affects Tonda: from n/a through <= 2.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57804

CodexThemes TheGem Theme Elements (for Elementor)

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor allows PHP Local File Inclusion.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.11.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57803

Select-Themes Struktur Core

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur Core allows PHP Local File Inclusion. This issue affects Struktur Core: from n/a before 2.7.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57802

Select-Themes Struktur

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur allows PHP Local File Inclusion. This issue affects Struktur: from n/a before 2.7.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57801

Select-Themes SetSail

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57800

Edge-Themes Overworld

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57799

uxper Nuss

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Nuss nuss allows PHP Local File Inclusion.This issue affects Nuss: from n/a through <= 1.3.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57798

SaurabhSharma NewsPlus Shortcodes

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SaurabhSharma NewsPlus Shortcodes newsplus-shortcodes allows PHP Local File Inclusion.This issue affects NewsPlus Shortcodes: from n/a through <= 4.2.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57796

VLThemes Leedo

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in VLThemes Leedo leedo allows PHP Local File Inclusion.This issue affects Leedo: from n/a through <= 3.0.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57795

themelexus Kitchor

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themelexus Kitchor kitchor allows PHP Local File Inclusion.This issue affects Kitchor: from n/a through <= 1.4.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57794

uxper Golo Framework

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.

The CVSS severity warrants an early asset and exposure review.