We get it — your site sits on a stack everyone else is trying to break. WebVuln™ is a working index of known web vulnerabilities for those platforms.
Total CVEs
6250
Stacks with data
16
High / critical
2687
Newest published
2026-07-26
| CVE | Stack | Summary | Severity | CVSS | Published | Detail |
|---|---|---|---|---|---|---|
| CVE-2026-63720 | Express | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to… | HIGH | 7.5 | Details | |
| CVE-2026-15962 | PHP | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via… | HIGH | 8.8 | Details | |
| CVE-2026-15962 | WordPress | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via… | HIGH | 8.8 | Details | |
| CVE-2026-64293 | Express | In the Linux kernel, the following vulnerability has been resolved: iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read The … | — | — | Details | |
| CVE-2026-15425 | WordPress | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | MEDIUM | 6.4 | Details | |
| CVE-2026-14955 | WordPress | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includ… | MEDIUM | 6.5 | Details | |
| CVE-2026-10818 | WordPress | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chu… | HIGH | 8.1 | Details | |
| CVE-2025-71408 | Express | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows a… | HIGH | 7.8 | Details | |
| CVE-2026-66033 | Express | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() f… | HIGH | 7.5 | Details | |
| CVE-2026-65693 | Express | Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve a… | HIGH | 7.2 | Details | |
| CVE-2026-8789 | WordPress | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing… | HIGH | 8.1 | Details | |
| CVE-2026-15663 | WordPress | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File … | MEDIUM | 4.9 | Details | |
| CVE-2026-15401 | WordPress | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all… | HIGH | 7.2 | Details | |
| CVE-2026-10033 | WordPress | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is du… | HIGH | 7.3 | Details | |
| CVE-2026-15821 | WordPress | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attrib… | MEDIUM | 6.4 | Details | |
| CVE-2026-15739 | WordPress | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute… | MEDIUM | 6.4 | Details | |
| CVE-2026-15346 | WordPress | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parame… | MEDIUM | 6.1 | Details | |
| CVE-2026-15755 | WordPress | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in … | MEDIUM | 6.4 | Details | |
| CVE-2026-15665 | WordPress | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redir… | MEDIUM | 6.4 | Details | |
| CVE-2026-15653 | WordPress | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… | MEDIUM | 6.4 | Details |
WebVuln™ lists NVD records that match our curated web-stack keywords — not personalized security advice. For your own site, run WebCheck™.