1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 2:05 PM 16,900 active 1,443 known exploited

Catalog summary

16,900

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 10, 2026, 2:05 PM 16,900 active 1,443 known exploited

Catalog summary

16,900

Active CVEs

8,491

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,651–5,700 of 16,900 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-27430High
    WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tranmautritam/TheFoxgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  2. CVE-2026-27426High
    WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themesuite/Automotive Car Dealership Businessgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  3. CVE-2026-27425High
    WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themesuite/Automotive Listingsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  4. CVE-2026-27419Critical
    WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability
    CVSS 9.9
    Zozothemes/Zegengeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  5. CVE-2026-27414High
    WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability
    CVSS 8.8
    Fuelthemes/Werkstattgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  6. CVE-2026-27412High
    WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerability
    CVSS 8.1
    StylemixThemes/Pearl - Corporate Businessgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  7. CVE-2026-27408High
    WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    imithemes/NativeChurchgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  8. CVE-2026-27404High
    WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Designthemes/LMSgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  9. CVE-2026-27402High
    WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Designthemes/Kids Life | Children School WordPressgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  10. CVE-2026-27060High
    WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability
    CVSS 8.8
    Repute Infosystems/ARMember Premiumgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  11. CVE-2025-69156High
    WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Design themes/Kids Zone - Children WordPress Themegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  12. CVE-2025-69155High
    WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Designthemes/Fitness Zone WordPress Themegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  13. CVE-2025-69154High
    WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    designthemes/SpaLab | Beauty Salon WordPress Themegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  14. CVE-2025-69153High
    WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    designthemes/Trendy Travelgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  15. CVE-2025-69152High
    WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    ThemeGoods/Artale | Wedding Photography WordPressgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  16. CVE-2025-69134High
    WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary Content Deletion vulnerability
    CVSS 7.5
    Merkulove/OpenAI Chatbot for WordPress – Helpergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  17. CVE-2025-69133High
    WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability
    CVSS 7.5
    GoodLayers/Tourmastergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  18. CVE-2025-69132Medium
    WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
    CVSS 6.5
    Zozothemes/Corpkitgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2025-69094High
    WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability
    CVSS 8.5
    ThemeMove/Unicampgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  20. CVE-2025-66076Medium
    WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vulnerability
    CVSS 5.3
    dylan ngo/Woostify Sites Librarygeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  21. CVE-2025-58902High
    WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability
    CVSS 8.1
    AncoraThemes/Lighthousegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2026-11946High
    GetEndpoints Memory Exhaustion in open62541
    CVSS 7.5
    open62541 project / o6 Automation GmbH/open62541generic
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  23. CVE-2026-13369High
    Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter
    CVSS 7.5
    SaturdayDrive/Ninja Forms - File Uploadsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  24. CVE-2026-13251High
    Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter
    CVSS 7.5
    perfmatters/Perfmattersgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  25. CVE-2026-14029Medium
    Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-10104Medium
    Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
    CVSS 4.4
    nikhilgadhiya/Product Video Gallery for Woocommercegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  27. CVE-2026-13252Medium
    RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute
    CVSS 6.4
    themeisle/RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregatorgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  28. CVE-2026-12472Medium
    Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters
    CVSS 5.3
    themeum/Kirki – Freeform Page Builder, Website Builder & Customizergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  29. CVE-2026-11896Medium
    My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter
    CVSS 5.3
    joedolson/My Calendar – Accessible Event Managergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  30. CVE-2026-12134Medium
    JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
    CVSS 4.3
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  31. CVE-2026-12122Medium
    Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action
    CVSS 5.3
    themeum/Kirki – Freeform Page Builder, Website Builder & Customizergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  32. CVE-2026-13459Medium
    JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
    CVSS 5.3
    jetmonsters/JetFormBuilder — Dynamic Blocks Form Buildergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  33. CVE-2026-12657Medium
    LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
    CVSS 5.3
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  34. CVE-2026-14336High
    CISA ADP Vulnrichment
    CVSS 8.2
    Eclipse Foundation/Eclipse CSI - PIAgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  35. CVE-2026-33592High
    FindServers Memory Exhaustion in open62541
    CVSS 7.5
    open62541 project / o6 Automation GmbH/open62541generic
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  36. CVE-2026-11965Medium
    User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass
    CVSS 6.5
    Unknown/User Registration & Membershipgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  37. CVE-2026-11781Low
    Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX
    CVSS 2.7
    Unknown/Adminifygeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  38. CVE-2026-11578Low
    Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR
    CVSS 2.7
    Unknown/Fluent Formsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  39. CVE-2026-10077Medium
    YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes
    CVSS 6.8
    Unknown/yoothemegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  40. CVE-2026-13704Medium
    GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
    CVSS 6.4
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  41. CVE-2026-10089Medium
    Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names)
    CVSS 6.4
    figureone/Insert Pagesgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  42. CVE-2026-11592Medium
    Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action
    CVSS 4.3
    icegram/Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  43. CVE-2026-13357Medium
    Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
    CVSS 4.9
    propertyhive/Houzez Property Feedgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  44. CVE-2026-14249High
    Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
    CVSS 7.5
    emarket-design/Request a Quote – Quote Forms for Any WordPress Sitegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  45. CVE-2026-11600Medium
    Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting
    CVSS 4.3
    envothemes/Envo's Templates & Widgets for Elementor and WooCommercegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  46. CVE-2026-13132High
    GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
    CVSS 8.3
    GeoVision Inc./GeoWebPlayergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  47. CVE-2026-13131High
    GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
    CVSS 8.3
    GeoVision Inc./GeoWebPlayergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  48. CVE-2026-13125High
    GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability
    CVSS 8.8
    GeoVision Inc./GeoWebPlayergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  49. CVE-2026-38968Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-38970High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 6, 2026View HOL analysis
Page 114 of 338
Previous112113114115116Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,491

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 5,651–5,700 of 16,900 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-27430High
    WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    tranmautritam/TheFoxgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  2. CVE-2026-27426High
    WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themesuite/Automotive Car Dealership Businessgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  3. CVE-2026-27425High
    WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Themesuite/Automotive Listingsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  4. CVE-2026-27419Critical
    WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability
    CVSS 9.9
    Zozothemes/Zegengeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  5. CVE-2026-27414High
    WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability
    CVSS 8.8
    Fuelthemes/Werkstattgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  6. CVE-2026-27412High
    WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerability
    CVSS 8.1
    StylemixThemes/Pearl - Corporate Businessgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  7. CVE-2026-27408High
    WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    imithemes/NativeChurchgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  8. CVE-2026-27404High
    WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Designthemes/LMSgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  9. CVE-2026-27402High
    WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Designthemes/Kids Life | Children School WordPressgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  10. CVE-2026-27060High
    WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability
    CVSS 8.8
    Repute Infosystems/ARMember Premiumgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Aug 3, 2026 Fix availableView HOL analysis
  11. CVE-2025-69156High
    WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Design themes/Kids Zone - Children WordPress Themegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  12. CVE-2025-69155High
    WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    Designthemes/Fitness Zone WordPress Themegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  13. CVE-2025-69154High
    WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    designthemes/SpaLab | Beauty Salon WordPress Themegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  14. CVE-2025-69153High
    WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    designthemes/Trendy Travelgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  15. CVE-2025-69152High
    WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerability
    CVSS 7.1
    ThemeGoods/Artale | Wedding Photography WordPressgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  16. CVE-2025-69134High
    WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary Content Deletion vulnerability
    CVSS 7.5
    Merkulove/OpenAI Chatbot for WordPress – Helpergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  17. CVE-2025-69133High
    WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability
    CVSS 7.5
    GoodLayers/Tourmastergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  18. CVE-2025-69132Medium
    WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
    CVSS 6.5
    Zozothemes/Corpkitgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  19. CVE-2025-69094High
    WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability
    CVSS 8.5
    ThemeMove/Unicampgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  20. CVE-2025-66076Medium
    WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vulnerability
    CVSS 5.3
    dylan ngo/Woostify Sites Librarygeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  21. CVE-2025-58902High
    WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability
    CVSS 8.1
    AncoraThemes/Lighthousegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  22. CVE-2026-11946High
    GetEndpoints Memory Exhaustion in open62541
    CVSS 7.5
    open62541 project / o6 Automation GmbH/open62541generic
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  23. CVE-2026-13369High
    Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter
    CVSS 7.5
    SaturdayDrive/Ninja Forms - File Uploadsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  24. CVE-2026-13251High
    Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter
    CVSS 7.5
    perfmatters/Perfmattersgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  25. CVE-2026-14029Medium
    Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter
    CVSS 6.5
    trainingbusinesspros/Groundhogg — CRM, Newsletters, and Marketing Automationgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  26. CVE-2026-10104Medium
    Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter
    CVSS 4.4
    nikhilgadhiya/Product Video Gallery for Woocommercegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  27. CVE-2026-13252Medium
    RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute
    CVSS 6.4
    themeisle/RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregatorgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  28. CVE-2026-12472Medium
    Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters
    CVSS 5.3
    themeum/Kirki – Freeform Page Builder, Website Builder & Customizergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  29. CVE-2026-11896Medium
    My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter
    CVSS 5.3
    joedolson/My Calendar – Accessible Event Managergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  30. CVE-2026-12134Medium
    JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action
    CVSS 4.3
    beardev/JoomSport – for Sports: Team & League, Football, Hockey & moregeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  31. CVE-2026-12122Medium
    Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action
    CVSS 5.3
    themeum/Kirki – Freeform Page Builder, Website Builder & Customizergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  32. CVE-2026-13459Medium
    JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter
    CVSS 5.3
    jetmonsters/JetFormBuilder — Dynamic Blocks Form Buildergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  33. CVE-2026-12657Medium
    LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter
    CVSS 5.3
    latepoint/LatePoint – Calendar Booking Plugin for Appointments and Eventsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  34. CVE-2026-14336High
    CISA ADP Vulnrichment
    CVSS 8.2
    Eclipse Foundation/Eclipse CSI - PIAgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  35. CVE-2026-33592High
    FindServers Memory Exhaustion in open62541
    CVSS 7.5
    open62541 project / o6 Automation GmbH/open62541generic
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  36. CVE-2026-11965Medium
    User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass
    CVSS 6.5
    Unknown/User Registration & Membershipgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  37. CVE-2026-11781Low
    Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX
    CVSS 2.7
    Unknown/Adminifygeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  38. CVE-2026-11578Low
    Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR
    CVSS 2.7
    Unknown/Fluent Formsgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  39. CVE-2026-10077Medium
    YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes
    CVSS 6.8
    Unknown/yoothemegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026 Fix availableView HOL analysis
  40. CVE-2026-13704Medium
    GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form
    CVSS 6.4
    stellarwp/GiveWP – Donation Plugin and Fundraising Platformgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  41. CVE-2026-10089Medium
    Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names)
    CVSS 6.4
    figureone/Insert Pagesgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  42. CVE-2026-11592Medium
    Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action
    CVSS 4.3
    icegram/Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  43. CVE-2026-13357Medium
    Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
    CVSS 4.9
    propertyhive/Houzez Property Feedgeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  44. CVE-2026-14249High
    Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter
    CVSS 7.5
    emarket-design/Request a Quote – Quote Forms for Any WordPress Sitegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  45. CVE-2026-11600Medium
    Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting
    CVSS 4.3
    envothemes/Envo's Templates & Widgets for Elementor and WooCommercegeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  46. CVE-2026-13132High
    GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
    CVSS 8.3
    GeoVision Inc./GeoWebPlayergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  47. CVE-2026-13131High
    GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability
    CVSS 8.3
    GeoVision Inc./GeoWebPlayergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  48. CVE-2026-13125High
    GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability
    CVSS 8.8
    GeoVision Inc./GeoWebPlayergeneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 2, 2026View HOL analysis
  49. CVE-2026-38968Critical
    CISA ADP Vulnrichment
    CVSS 9.8
    n/a/n/ageneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 8, 2026View HOL analysis
  50. CVE-2026-38970High
    CISA ADP Vulnrichment
    CVSS 7.5
    n/a/n/ageneric
    PublishedJul 2, 2026First seen at HOL Jul 2, 2026Updated Jul 6, 2026View HOL analysis
Page 114 of 338
Previous112113114115116Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard