VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 367 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57423

Kofi Mokome Message Filter for Contact Form 7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57422

VillaTheme Bopo – WooCommerce Product Bundle Builder

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57421

CRM Perks CRM Perks Forms

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57417

RexTheme Cart Lift

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Cart Lift cart-lift allows Stored XSS.This issue affects Cart Lift: from n/a through <= 3.1.57.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57416

SiteGround SiteGround Email Marketing

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57415

Codemenschen Gift Vouchers

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57411

Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aman CF7 Views &#8211; Complete Entry Management for Contact Form 7 cf7-views allows DOM-Based XSS.This issue affects CF7 Views &#8211; Complete Entry Management for Contact Form 7: from n/a through <= 3.2.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57410

MailerPress Team MailerPress

Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57409

RealMag777 Active Products Tables for WooCommerce

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57407

WP Swings PDF Generator for WordPress

Server-Side Request Forgery (SSRF) vulnerability in WP Swings PDF Generator for WordPress pdf-generator-for-wp allows Server Side Request Forgery.This issue affects PDF Generator for WordPress: from n/a through <= 1.6.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57405

themehunk Open Shop

Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57403

Milan Petrovic GD Security Headers

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Security Headers gd-security-headers allows Reflected XSS.This issue affects GD Security Headers: from n/a through <= 1.8.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-57401

Brainstorm Force SureDash

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57399

Proxy &amp; VPN Blocker

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57398

WebCodingPlace Real Estate Manager Pro

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3.

The CVSS severity warrants an early asset and exposure review.