7.5 CVE-2026-42566
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node...

2026-07-20T00:16:58.050

10 CVE-2026-44359
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic...

2026-07-20T19:17:22.790

5.4 CVE-2026-45138
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom...

2026-07-20T14:16:56.853

8.8 CVE-2026-10081
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google...

2026-07-20T14:16:52.417

4.8 CVE-2026-10724
The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in...

2026-07-20T14:16:52.570

2.7 CVE-2026-10755
The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its...

2026-07-20T14:16:52.713

8.6 CVE-2026-11349
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress...

2026-07-20T20:39:31.217

5.3 CVE-2026-11868
The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its...

2026-07-20T20:39:31.217

7.5 CVE-2026-12592
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation...

2026-07-20T20:39:31.217

5.3 CVE-2026-12723
The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST...

2026-07-20T20:39:31.217

4.3 CVE-2026-12724
The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values...

2026-07-20T20:39:31.217

6.5 CVE-2026-12898
The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied...

2026-07-20T20:39:31.217

7.1 CVE-2026-12970
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it...

2026-07-20T20:39:31.217

5.3 CVE-2026-12972
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership...

2026-07-20T16:16:54.900

6.5 CVE-2026-12973
The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership...

2026-07-20T16:16:55.050

CVE-2026-13142
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce...

2026-07-20T07:16:35.483

9.1 CVE-2026-13147
The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it...

2026-07-20T20:39:31.217

5.4 CVE-2026-13156
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete...

2026-07-20T20:39:31.217

5.4 CVE-2026-13432
The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX...

2026-07-20T20:39:31.217

9.8 CVE-2026-16235
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions...

2026-07-20T19:17:19.980

7.5 CVE-2026-6656
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password...

2026-07-20T19:17:30.503