Skip to main content

Year archive

CVEs published in 2026

Archive summary

51,879 CVEs published in 2026 — 5,760 Critical, 20,805 High, 20,226 Medium, 4,055 Low, 1,033 Unrated.

CVE-2026-25033

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uixthemes Motta Addons motta-addons allows Reflected XSS.This issue affects M…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25032

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-25031

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-25030

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-25029

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-25026

Published Mar 25, 2026

Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25025

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affect…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25018

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25017

Published Mar 25, 2026

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25013

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25009

Published Mar 25, 2026

Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-25007

Published Mar 25, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25002

Published Mar 25, 2026

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affe…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-25001

Published Mar 25, 2026

Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: fr…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24993

Published Mar 25, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advan…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-24989

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-24987

Published Mar 25, 2026

Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Syst…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-24983

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects Up…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24981

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24980

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue af…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24979

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobi…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24978

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24977

Published Mar 25, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.Thi…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24976

Published Mar 25, 2026

Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <=…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24975

Published Mar 25, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issu…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Showing 38,026-38,050 of 51,879 CVEsPage 1522 of 2076