Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-9815

MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE_CVE-2026-9815

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a fo...

Unknown MagicForm CVE
MEDIUM 5.4 CVE-2026-55745

Cotonti CSRF in PFS folder edit allows unauthorized folder modification_CVE-2026-55745

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pf...

Cotonti Cotonti 1.0.0 CVE
MEDIUM 6.1 CVE-2026-12137

SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameter_CVE-2026-12137

The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is vulnerable to Reflected Cr...

phppoet SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager CVE
MEDIUM 6.4 CVE-2026-12136

SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes_CVE-2026-12136

The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysbasics_user_avatar' shortcod...

phppoet SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager CVE
MEDIUM 4.3 CVE-2026-12111

Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter_CVE-2026-12111

The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. Thi...

codepeople Appointment Booking Calendar CVE
MEDIUM 6.4 CVE-2026-12098

PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field_CVE-2026-12098

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed' Episode Meta Field in all...

blubrry PowerPress Podcasting plugin by Blubrry CVE
MEDIUM 6.4 CVE-2026-8039

Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting_CVE-2026-8039

The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' ...

dijitul Fancy Testimonials CVE
MEDIUM 5.1 CVE-2026-50643

Out‑of‑Bounds Read in 8cc_CVE-2026-50643

8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compiler accepts attacker-controll...

rui314 8cc b480958 CVE
MEDIUM 6.4 CVE-2026-2021

Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute_CVE-2026-2021

The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versio...

contrid Slideshow Gallery LITE CVE
MEDIUM 5.9 CVE-2026-56007

WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability_CVE-2026-56007

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Product Sharing allows Stored X...

OceanWP Ocean Product Sharing n/a CVE