Skip to main content

Severity archive

High severity CVEs

High

129,227 high severity CVEs — 44,577 Critical, 129,227 High, 164,237 Medium, 18,292 Low, 1,994 Unrated across the current result set.

CVE-2026-73346

Published Aug 13, 2026

Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.

CVSS 7.6 · High
evidence mentions
1

CVE-2026-73188

Published Aug 13, 2026

Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66704

Published Aug 13, 2026

Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.

CVSS 7.2 · High
evidence mentions
1

CVE-2026-66700

Published Aug 13, 2026

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

CVSS 7.1 · High
evidence mentions
1

CVE-2026-66698

Published Aug 13, 2026

Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.

CVSS 7.1 · High
evidence mentions
1

CVE-2026-66697

Published Aug 13, 2026

Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

CVSS 7.1 · High
evidence mentions
1

CVE-2026-66661

Published Aug 13, 2026

Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.

CVSS 7.7 · High
evidence mentions
1

CVE-2026-66658

Published Aug 13, 2026

Subscriber SQL Injection in Reviewer <= 3.14.2 versions.

CVSS 8.5 · High
evidence mentions
1

CVE-2026-66657

Published Aug 13, 2026

Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.

CVSS 8.1 · High
evidence mentions
1

CVE-2026-66656

Published Aug 13, 2026

Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.

CVSS 8.1 · High
evidence mentions
1

CVE-2026-66655

Published Aug 13, 2026

Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.

CVSS 7.1 · High
evidence mentions
1

CVE-2026-66653

Published Aug 13, 2026

Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.

CVSS 8.1 · High
evidence mentions
1

CVE-2026-66469

Published Aug 13, 2026

Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66468

Published Aug 13, 2026

Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.

CVSS 7.1 · High
evidence mentions
1

CVE-2026-66466

Published Aug 13, 2026

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66463

Published Aug 13, 2026

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66462

Published Aug 13, 2026

Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66461

Published Aug 13, 2026

Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66450

Published Aug 13, 2026

Unauthenticated Local File Inclusion in Geo Mashup <= 1.13.18 versions.

CVSS 8.1 · High
evidence mentions
1

CVE-2026-66449

Published Aug 13, 2026

Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.

CVSS 7.1 · High
evidence mentions
1

CVE-2026-66443

Published Aug 13, 2026

Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66441

Published Aug 13, 2026

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66432

Published Aug 13, 2026

Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66431

Published Aug 13, 2026

Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.

CVSS 7.5 · High
evidence mentions
1

CVE-2026-66430

Published Aug 13, 2026

Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.

CVSS 8.5 · High
evidence mentions
1
Showing 1-25 of 129,227 CVEsPage 1 of 5170