| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65492 | Hig | 0.46 | 7.1 | 0.00 | Jul 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS. This issue affects Dokan Pro: from n/a before 5.0.7. | ||
| CVE-2026-65491 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. | ||
| CVE-2026-65490 | Med | 0.34 | 5.3 | 0.00 | Jul 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0. | ||
| CVE-2026-65489 | Med | 0.34 | 5.3 | 0.00 | Jul 23, 2026 | Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | ||
| CVE-2026-65488 | Hig | 0.46 | 7.1 | 0.00 | Jul 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | ||
| CVE-2026-65487 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | ||
| CVE-2026-65486 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | ||
| CVE-2026-65485 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | ||
| CVE-2026-65484 | Med | 0.00 | 6.3 | 0.00 | Jul 23, 2026 | Contributor Broken Access Control in Style Kits <= 2.6.5 versions. | ||
| CVE-2026-65483 | Med | 0.00 | 5.9 | 0.00 | Jul 23, 2026 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | ||
| CVE-2026-65482 | Med | 0.42 | 6.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows DOM-Based XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.3. | ||
| CVE-2026-65481 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Contributor Local File Inclusion in Vino <= 1.9 versions. | ||
| CVE-2026-65480 | Med | 0.42 | 6.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1. | ||
| CVE-2026-65479 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | ||
| CVE-2026-65478 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. | ||
| CVE-2026-65477 | Hig | 0.00 | 7.5 | 0.00 | Jul 23, 2026 | Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. | ||
| CVE-2026-65476 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. | ||
| CVE-2026-65475 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. | ||
| CVE-2026-65474 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | ||
| CVE-2026-65473 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions. | ||
| CVE-2026-65472 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. | ||
| CVE-2026-65471 | Cri | 0.00 | 9.6 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. | ||
| CVE-2026-65470 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | ||
| CVE-2026-65469 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. | ||
| CVE-2026-65468 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | ||
| CVE-2026-65467 | Med | 0.00 | 4.9 | 0.00 | Jul 23, 2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | ||
| CVE-2026-65466 | Med | 0.00 | 4.9 | 0.00 | Jul 23, 2026 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | ||
| CVE-2026-65465 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. | ||
| CVE-2026-65464 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. | ||
| CVE-2026-65463 | Med | 0.00 | 5.4 | 0.00 | Jul 23, 2026 | Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. | ||
| CVE-2026-65462 | Hig | 0.00 | 7.6 | 0.00 | Jul 23, 2026 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. | ||
| CVE-2026-65461 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | ||
| CVE-2026-65460 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. | ||
| CVE-2026-65458 | Med | 0.28 | 4.3 | 0.00 | Jul 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5. | ||
| CVE-2026-65457 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. | ||
| CVE-2026-65456 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions. | ||
| CVE-2026-65455 | Cri | 0.00 | 9.1 | 0.01 | Jul 23, 2026 | Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-65454 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | ||
| CVE-2026-65453 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | ||
| CVE-2026-65452 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | ||
| CVE-2026-65451 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-65450 | Hig | 0.00 | 8.5 | 0.00 | Jul 23, 2026 | Contributor SQL Injection in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-65449 | Med | 0.00 | 6.5 | 0.00 | Jul 23, 2026 | Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. | ||
| CVE-2026-64815 | Hig | 0.00 | 8.1 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | ||
| CVE-2026-64814 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | ||
| CVE-2026-64813 | Cri | 0.00 | 10.0 | 0.01 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | ||
| CVE-2026-64812 | Cri | 0.00 | 10.0 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session | ||
| CVE-2026-64811 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | ||
| CVE-2026-64810 | Med | 0.00 | 4.3 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking | ||
| CVE-2026-64809 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter |
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS. This issue affects Dokan Pro: from n/a before 5.0.7.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
- risk 0.34cvss 5.3epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in John-Michael L'Allier Create mediavine-create allows Retrieve Embedded Sensitive Data.This issue affects Create: from n/a through 2.6.0.
- risk 0.34cvss 5.3epss 0.00
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
- risk 0.46cvss 7.1epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
- risk 0.00cvss 6.3epss 0.00
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
- risk 0.00cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
- risk 0.42cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows DOM-Based XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.3.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Vino <= 1.9 versions.
- risk 0.42cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem allows DOM-Based XSS. This issue affects TheGem: from n/a before 5.12.1.1.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
- risk 0.00cvss 7.5epss 0.00
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
- risk 0.00cvss 6.5epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.
- risk 0.00cvss 9.6epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
- risk 0.00cvss 4.9epss 0.00
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
- risk 0.00cvss 4.9epss 0.00
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
- risk 0.00cvss 5.4epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.
- risk 0.00cvss 5.4epss 0.00
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.
- risk 0.00cvss 7.6epss 0.00
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
- risk 0.00cvss 9.1epss 0.01
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
- risk 0.00cvss 4.3epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.
- risk 0.28cvss 4.3epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.
- risk 0.00cvss 4.3epss 0.00
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.
- risk 0.00cvss 4.3epss 0.00
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
- risk 0.00cvss 9.1epss 0.01
Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 8.5epss 0.00
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
- risk 0.00cvss 8.1epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
- risk 0.00cvss 8.6epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.01
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
- risk 0.00cvss 10.0epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
- risk 0.00cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
- risk 0.00cvss 4.3epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
- risk 0.00cvss 8.4epss 0.00
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter