🛡️ CVE Intelligence Center
Common Vulnerabilities & Exposures — Security Intelligence Database
| CVE ID | Severity | CVSS | Description | Status | Published |
|---|---|---|---|---|---|
| CVE-2025-13910 | Medium | 6.1 |
The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJA…
|
— | Mar 21, 2026 |
| CVE-2026-3572 | Medium | 6.1 |
The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting …
|
— | Mar 21, 2026 |
| CVE-2026-2427 | Medium | 6.1 |
The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' param…
|
— | Mar 21, 2026 |
| CVE-2026-2723 | Medium | 6.1 |
The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,…
|
— | Mar 21, 2026 |
| CVE-2026-2277 | Medium | 6.1 |
The rexCrawler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' and 'regex' parameters…
|
— | Mar 21, 2026 |
| CVE-2026-32057 | Medium | 5.9 |
OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair…
|
— | Mar 21, 2026 |
| CVE-2026-32045 | Medium | 5.9 |
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes,…
|
— | Mar 21, 2026 |
| CVE-2024-13785 | Medium | 5.6 |
The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc…
|
— | Mar 21, 2026 |
| CVE-2026-3347 | Medium | 5.5 |
The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[me…
|
— | Mar 21, 2026 |
| CVE-2019-25554 | Medium | 5.5 |
Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the applica…
|
— | Mar 21, 2026 |
| CVE-2019-25559 | Medium | 5.5 |
SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local atta…
|
— | Mar 21, 2026 |
| CVE-2019-25562 | Medium | 5.5 |
jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to …
|
— | Mar 21, 2026 |
| CVE-2019-25564 | Medium | 5.5 |
PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by …
|
— | Mar 21, 2026 |
| CVE-2019-25570 | Medium | 5.5 |
RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash the ap…
|
— | Mar 21, 2026 |
| CVE-2019-25577 | Medium | 5.5 |
SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arb…
|
— | Mar 21, 2026 |
| CVE-2026-32044 | Medium | 5.5 |
OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypas…
|
— | Mar 21, 2026 |
| CVE-2026-32895 | Medium | 5.4 |
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event han…
|
— | Mar 21, 2026 |
| CVE-2026-32898 | Medium | 5.4 |
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves …
|
— | Mar 21, 2026 |
| CVE-2026-3335 | Medium | 5.3 |
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th…
|
— | Mar 21, 2026 |
| CVE-2026-1253 | Medium | 5.3 |
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a…
|
— | Mar 21, 2026 |