Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.7 CVE-2026-9710

Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Password Hash Disclosure_CVE-2026-9710

The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce ...

Unknown Cornerstone 3.0.0 CVE
HIGH 7.7 CVE-2026-9709

Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Meta Disclosure_CVE-2026-9709

The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to ...

Unknown Cornerstone 3.0.0 CVE
LOW 2.7 CVE-2026-10753

Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update_CVE-2026-10753

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-priv...

Unknown Site Kit by Google CVE
HIGH 7.2 CVE-2026-10749

Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData_CVE-2026-10749

The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied seria...

Unknown Post Duplicator CVE
HIGH 7.5 CVE-2026-10735

ShapedPlugin Multiple Pro Plugins – Backdoor via Compromised Vendor Update Server_CVE-2026-10735

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommer...

Unknown smart-post-show-pro 4.0.1 CVE
MEDIUM 5.4 CVE-2026-10531

AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortcode Attribute_CVE-2026-10531

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a pa...

Unknown AI Share & Summarize CVE
MEDIUM 5.3 CVE-2026-56761

hono – HTML Injection via Improper JSX Attribute Name Handling in SSR_CVE-2026-56761

hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using ...

hono hono CVE
MEDIUM 4.8 CVE-2026-56370

ImageMagick – Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact_CVE-2026-56370

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artif...

ImageMagick ImageMagick CVE
MEDIUM 6.3 CVE-2026-56368

ImageMagick – Memory Leak in Raw Pixel Data Coders_CVE-2026-56368

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not prope...

ImageMagick ImageMagick CVE
MEDIUM 5.1 CVE-2026-56358

n8n – Stored Cross-Site Scripting in Form Trigger Node_CVE-2026-56358

n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in th...

n8n n8n CVE