Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-8840: CWE-862 Missing Authorization in wpdevart Booking calendar, Appointment Booking SystemCVE-2026-8840
0

The Booking calendar, Appointment Booking System plugin for WordPress contains an authorization bypass vulnerability in all versions up to and including 3.2.36. This flaw allows unauthenticated attackers to manipulate reservation statuses, cancel payments, auto-approve bookings (if a specific site option is enabled), and trigger booking-related emails by injecting crafted payment status and transaction data into the payments table.

Join the discussion
CVE-2026-16080: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in fishpie Image Uploader for WelcartCVE-2026-16080
0

The Image Uploader for Welcart WordPress plugin contains a SQL Injection vulnerability in the 'post_title' parameter in all versions up to and including 1.4.6. Authenticated users with author-level access or higher can exploit this flaw to append additional SQL queries, potentially extracting sensitive database information. The vulnerability arises from insufficient escaping and lack of proper query preparation. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-15965: CWE-434 Unrestricted Upload of File with Dangerous Type in sadathimel MaxUpload – Big File Uploads – Increase Maximum File Upload SizeCVE-2026-15965
0

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size WordPress plugin contains an arbitrary file upload vulnerability in all versions up to and including 1.4.0. This occurs due to improper validation of the final assembled filename, allowing unauthenticated attackers to upload potentially executable files. This vulnerability can lead to remote code execution.

Join the discussion
CVE-2026-15341: CWE-287 Improper Authentication in rafasashi User Session SynchronizerCVE-2026-15341
0

The User Session Synchronizer plugin for WordPress contains an authentication bypass vulnerability in all versions up to and including 1.4.0. The vulnerability arises because the synchronize_session() function does not validate critical parameters, allowing attackers to impersonate any user, including administrators, without prior knowledge of site secrets.

Join the discussion
CVE-2026-15312: CWE-269 Improper Privilege Management in fassionstorage Propovoice: All-in-One Client Management SystemCVE-2026-15312
0

The Propovoice: All-in-One Client Management System WordPress plugin contains a privilege escalation vulnerability in all versions up to and including 1.7.8. The vulnerability arises because the REST endpoint for the create() function does not properly validate the user-supplied role parameter and lacks a capability check before assigning roles. This allows authenticated users with the ndpv_manager capability or higher to create new administrator accounts, resulting in full vertical privilege escalation.

Join the discussion
CVE-2026-15303: CWE-287 Improper Authentication in sixstorage 6Storage RentalsCVE-2026-15303
0

The 6Storage Rentals WordPress plugin contains a critical authentication bypass vulnerability in versions up to and including 2.27.0. This flaw allows unauthenticated attackers to log in as any existing WordPress user, including administrators, by exploiting an AJAX handler that lacks proper verification. The vulnerability arises because the six_storage_create_wp_user() AJAX handler is registered without nonce, capability, credential, or ownership checks, enabling attackers to impersonate users by submitting their email addresses.

Join the discussion
CVE-2026-15162: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in minnpost Object Sync for SalesforceCVE-2026-15162
0

The Object Sync for Salesforce WordPress plugin contains an unauthenticated SQL Injection vulnerability in its /wp-json/object-sync-for-salesforce/push/ REST route via the wordpress_object_type parameter. The route lacks proper permission checks beyond the HTTP method, allowing unauthenticated attackers to inject arbitrary SQL queries. This can lead to extraction of sensitive data such as password hashes from the database. A patch is available, and since this is a cloud-hosted service, the vendor manages remediation.

Join the discussion
CVE-2026-15001: CWE-269 Improper Privilege Management in connectordev bLoyal: Loyalty & Promotions by bLoyalCVE-2026-15001
0

The bLoyal: Loyalty & Promotions by bLoyal WordPress plugin contains a privilege escalation vulnerability in all versions up to and including 3.1.611.78. This flaw allows authenticated users with Subscriber-level access or higher to manipulate unprotected AJAX actions to overwrite critical plugin settings and subsequently authenticate as any WordPress user, including administrators. The vulnerability arises from missing capability and nonce checks on AJAX actions and improper trust in external API data for automatic customer login.

Join the discussion
CVE-2026-14484: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in pietror91 RapiSafe – Secure Multi File Upload for Contact Form 7CVE-2026-14484
0

The RapiSafe – Secure Multi File Upload for Contact Form 7 WordPress plugin up to version 1.0.4 contains a path traversal vulnerability that allows unauthenticated attackers to delete arbitrary files on the server. This is due to insufficient validation of file paths in the handleAjaxRemoveUpload function. The required nonce to trigger the file removal is exposed in public JavaScript on pages with the RapiSafe upload field, making it accessible to any visitor. Exploitation can lead to remote code execution if critical files like wp-config.php are deleted.

Join the discussion
CVE-2026-14433: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vcita Online Booking & Scheduling Calendar for WordPress by vcitaCVE-2026-14433
0

The Online Booking & Scheduling Calendar for WordPress by vcita plugin is affected by a stored cross-site scripting (XSS) vulnerability via the 'business_id' parameter in all versions up to and including 4.6.0. This vulnerability allows unauthenticated attackers to inject arbitrary scripts that execute when users access the affected pages. The vulnerability is due to insufficient input sanitization and output escaping.

Join the discussion

Showing 1 to 10 of 24141 results

Filters:Package: pkg:generic/libredwg
Page 1 of 2415
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses