VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 366 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57718

Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 2.0.12.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57715

WPManageNinja Fluent CRM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPManageNinja Fluent CRM fluent-crm allows Reflected XSS.This issue affects Fluent CRM: from n/a through <= 3.1.7.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57714

LatePoint

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through <= 5.6.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57713

Marcus (aka @msykes) Events Manager

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57712

WPZOOM WPZOOM Portfolio

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57710

quantumcloud WoowBot Pro Max

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57709

WP Swings Membership For WooCommerce

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57708

CRM Perks Contact Form Entries

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57707

quantumcloud Simple Business Directory Pro

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57706

Dokan, Inc. Dokan

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57705

Nexcess Event Tickets

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57702

Melograno Venture Studio Amelia

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57697

Metagauss ProfileGrid

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57695

Dan Rossiter Document Gallery

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57668

Basix NEX-Forms

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2.

The CVSS severity warrants an early asset and exposure review.