Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 4.3 CVE-2026-12111

Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter_CVE-2026-12111

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. Thi...

codepeople Appointment Booking Calendar CVE
MEDIUM 6.4 CVE-2026-12098

PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field_CVE-2026-12098

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all...

blubrry PowerPress Podcasting plugin by Blubrry CVE
MEDIUM 6.4 CVE-2026-8039

Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting_CVE-2026-8039

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' ...

dijitul Fancy Testimonials CVE
MEDIUM 5.1 CVE-2026-50643

Out‑of‑Bounds Read in 8cc_CVE-2026-50643

8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controll...

rui314 8cc b480958 CVE
MEDIUM 6.4 CVE-2026-2021

Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute_CVE-2026-2021

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versio...

contrid Slideshow Gallery LITE CVE
MEDIUM 5.9 CVE-2026-56007

WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56007

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored X...

OceanWP Ocean Product Sharing n/a CVE
MEDIUM 6.5 CVE-2026-44942

libzypp .repo files can have an optional path which can lead to path traversal attacks_CVE-2026-44942

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could ...

SUSE libzypp 17.0.0 CVE
MEDIUM 5.9 CVE-2026-56009

WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56009

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored X...

Bricksable Bricksable for Bricks Builder n/a CVE
MEDIUM 5.1 CVE-2026-54221

Reflected XSS in UBB.threads_CVE-2026-54221

UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitr...

UBB Systems UBB.threads CVE
MEDIUM 5.1 CVE-2026-54219

Stored XSS in UBB.threads_CVE-2026-54219

UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low...

UBB Systems UBB.threads CVE