VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 364 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57793

Elated-Themes Flow

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Flow flow allows PHP Local File Inclusion.This issue affects Flow: from n/a through <= 1.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57792

Mikado-Themes Dør

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57791

ThemeMove Brook

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57790

ThemeMove Billey

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through <= 2.1.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57789

jwsthemes Aqua

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57788

Edge-Themes Aalto

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Aalto aalto allows PHP Local File Inclusion.This issue affects Aalto: from n/a through <= 1.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57787

CreativeWS CWS SVGicons

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through <= 1.5.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57786

purethemes WorkScout-Core

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout-Core: from n/a through <= 1.7.08.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57773

Zorem Advanced Shipment Tracking for WooCommerce

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57772

WP Inventory WP Inventory Manager

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57771

Milan Petrovic GD Rating System

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57770

ThemeGoods Grand Photography

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57768

favethemes Houzez Login Register

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57745

stmcan RT-Theme 18 | Extensions

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57744

stmcan RT-Theme 18 | Extensions

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.

The CVSS severity warrants an early asset and exposure review.