VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,287 CVE recordsPage 368 of 1286 · EPSS data 2026.07.20
ReviewHigh
CVE-2026-57396

Flintop Free Gifts for WooCommerce

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Flintop Free Gifts for WooCommerce free-gifts-for-woocommerce allows Stored XSS.This issue affects Free Gifts for WooCommerce: from n/a through <= 13.1.0.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57394

Tribulant Software Newsletters

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57389

Adrian Tobey Groundhogg

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57388

Themefic Hydra Booking

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57387

picu

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through <= 3.5.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57386

Kodezen LLC aBlocks

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57385

appsbd Vitepos

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57383

eyecix JobSearch

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57382

Mitchell Bennis Simple File List

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57381

Property Hive PropertyHive

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57380

hupe13 Extensions for Leaflet Map

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57379

WPPOOL FormyChat

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57378

Phil Kurth Advanced Forms

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57376

Element Invader ElementInvader Addons for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows DOM-Based XSS.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.3.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-57372

denishua WPJAM Basic

Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basic: from n/a through <= 7.0.

The CVSS severity warrants an early asset and exposure review.