Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-85418: CWE-79 Cross-Site Scripting (XSS) in Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & MoreCVE-2026-85418
0

CVE-2026-85418 is a cross-site scripting (XSS) vulnerability in the WordPress plugin Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More. Versions before 3.0.9 do not properly validate user-supplied HTML tag names in a Beaver Builder widget, allowing users with contributor-level access or higher to inject arbitrary scripts. These scripts execute when any visitor views the affected page, potentially leading to client-side attacks. No official patch or remediation guidance is currently available from the vendor. No known exploits in the wild have been reported.

Join the discussion
CVE-2026-85133: CWE-862 Missing Authorization in WPLP Cookie ConsentCVE-2026-85133
0

WPLP Cookie Consent WordPress plugin versions before 4.4.2 lack proper authorization checks on several AJAX settings actions. This allows any authenticated user, including low-privilege roles like subscribers, to read and delete administrator scan data and overwrite the plugin's stored configuration.

Join the discussion
CVE-2026-85132: CWE-862 Missing Authorization in WPLP Cookie ConsentCVE-2026-85132
0

WPLP Cookie Consent WordPress plugin versions before 4.4.2, including version 4.0.2, contains a missing authorization vulnerability. The plugin does not perform nonce or capability checks on one of its cookie scanner AJAX actions, allowing any authenticated user, such as a subscriber, to read the automated scan schedule configured by the administrator.

Join the discussion
CVE-2026-85037: CWE-639 Authorization Bypass Through User-Controlled Key in Sunshine Photo CartCVE-2026-85037
0

Sunshine Photo Cart WordPress plugin versions before 3.7 contain an authorization bypass vulnerability. The plugin does not validate that a client-supplied price identifier corresponds to the item being purchased. This allows unauthenticated users to purchase items at unauthorized lower prices defined elsewhere on the site, potentially causing financial loss to the site owner.

Join the discussion
CVE-2026-84222: CWE-200 Information Exposure in KirkiCVE-2026-84222
0

CVE-2026-84222 is an information exposure vulnerability in the Kirki WordPress plugin versions before 6.3.0. The plugin fails to verify if a requester has permission to read a post before rendering and returning its content. This allows unauthenticated users to access content of pages that are not publicly available, including private, draft, pending, and trashed pages.

Join the discussion
CVE-2026-84113: CWE-89 SQL Injection in Quentn WPCVE-2026-84113
0

CVE-2026-84113 is a SQL Injection vulnerability in the Quentn WP WordPress plugin versions before 1.2.15. The plugin fails to properly sanitize and escape a parameter before including it in an SQL query. This flaw allows users with high privileges, such as administrators, to perform SQL injection attacks.

Join the discussion
CVE-2026-84068: CWE-89 SQL Injection in Quentn WPCVE-2026-84068
0

A SQL injection vulnerability exists in the Quentn WP WordPress plugin version 1.2.13. The plugin fails to properly escape a request parameter before using it in an unprepared SQL query, which allows unauthenticated attackers to extract arbitrary data from the database.

Join the discussion
CVE-2026-83541: CWE-79 Cross-Site Scripting (XSS) in Sina Extension for ElementorCVE-2026-83541
0

CVE-2026-83541 is a stored Cross-Site Scripting (XSS) vulnerability in the Sina Extension for Elementor WordPress plugin. Versions including and specifically version 3.7.1 do not properly escape a Table widget setting before outputting it within an HTML attribute. This flaw allows users with Contributor role or higher to inject malicious scripts that persist and execute in other users' browsers.

Join the discussion
CVE-2026-82848: CWE-862 Missing Authorization in Masteriyo LMSCVE-2026-82848
0

Masteriyo LMS WordPress plugin versions before 3.4.0 lack proper authorization checks in their REST API when returning course enrolment records. This allows unauthenticated users to access any learner's enrolment status, timestamps, and course progress by iterating through sequential record IDs. Additionally, any enrolled user can retrieve enrolment records of other learners. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-82185: CWE-862 Missing Authorization in WPLP Cookie ConsentCVE-2026-82185
0

The WPLP Cookie Consent WordPress plugin before version 4.4.2 lacks proper authorization checks on certain A/B testing actions. This vulnerability allows any authenticated user, including low-privilege roles like subscribers, to overwrite the cookie banner configuration visible to all visitors and to irreversibly reset stored A/B test results.

Join the discussion

Showing 1 to 10 of 19047 results

Filters:Package: pkg:bitnami/moodle
Page 1 of 1905
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses