| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5488 | ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token' | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | Medium | 5.3 | 2026-04-24 03:27:06 | Deep Dive |
| CVE-2026-5464 | ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | High | 7.2 | 2026-04-23 08:28:26 | Deep Dive |
| CVE-2026-3574 | Experto Dashboard for WooCommerce <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Navigation Font Size' Setting | uxdexperts | Experto Dashboard for WooCommerce | Medium | 4.4 | 2026-04-09 02:25:06 | Deep Dive |
| CVE-2026-20174 | Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability | Cisco | Cisco Nexus Dashboard | Medium | 4.9 | 2026-04-01 16:29:23 | Deep Dive |
| CVE-2026-20041 | Cisco Nexus Dashboard Server Side Request Forgery Vulnerability | Cisco | Cisco Nexus Dashboard | Medium | 6.1 | 2026-04-01 16:27:50 | Deep Dive |
| CVE-2026-20042 | Cisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability | Cisco | Cisco Nexus Dashboard | Medium | 6.5 | 2026-04-01 16:27:50 | Deep Dive |
| CVE-2026-3527 | AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022 | Drupal | AJAX Dashboard | - | - | 2026-03-26 20:03:06 | Deep Dive |
| CVE-2026-1992 | ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | High | 8.8 | 2026-03-11 09:25:43 | Deep Dive |
| CVE-2026-1993 | ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | High | 8.8 | 2026-03-11 09:25:42 | Deep Dive |
| CVE-2026-2410 | Disable Admin Notices – Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update | themeisle | Disable Admin Notices – Hide Dashboard Notifications | Medium | 4.3 | 2026-02-25 09:26:51 | Deep Dive |
| CVE-2026-27595 | Parse Dashboard has incomplete authentication on AI Agent endpoint | parse-community | parse-dashboard | - | - | 2026-02-25 02:21:33 | Deep Dive |
| CVE-2026-27610 | Parse Dashboard Has a Cache Key Collision that Leaks Master Key to Read-Only Sessions | parse-community | parse-dashboard | - | - | 2026-02-25 02:19:56 | Deep Dive |
| CVE-2026-27609 | Parse Dashboard Missing CSRF Protection on Agent Endpoint | parse-community | parse-dashboard | - | - | 2026-02-25 02:18:29 | Deep Dive |
| CVE-2026-27608 | Parse Dashboard Missing Authorization on Agent Endpoint | parse-community | parse-dashboard | - | - | 2026-02-25 02:16:31 | Deep Dive |
| CVE-2026-25069 | SunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/Deletion | SunFounder | Pironman Dashboard (pm_dashboard) | - | - | 2026-01-31 23:47:00 | Deep Dive |
| CVE-2025-14616 | Recooty <= 1.0.6 - Cross-Site Request Forgery to Settings Update | recooty | Recooty – Job Widget (Old Dashboard) | Medium | 4.3 | 2026-01-28 11:23:42 | Deep Dive |
| CVE-2025-14615 | DASHBOARD BUILDER <= 1.5.7 - Cross-Site Request Forgery to SQL Injection | dashboardbuilder | DASHBOARD BUILDER – WordPress plugin for Charts and Graphs | High | 7.1 | 2026-01-14 05:28:04 | Deep Dive |
| CVE-2026-22488 | WordPress Dashboard Welcome for Beaver Builder plugin <= 1.0.8 - Broken Access Control vulnerability | IdeaBox Creations | Dashboard Welcome for Beaver Builder | Medium | 5.3 | 2026-01-08 16:35:04 | Deep Dive |
| CVE-2025-12540 | ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposure | sharethis | ShareThis Dashboard for Google Analytics | Medium | 4.7 | 2026-01-07 08:21:53 | Deep Dive |
| CVE-2025-12449 | aBlocks – WordPress Gutenberg Blocks <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Settings Modification | kodezen | aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder | Medium | 5.4 | 2026-01-07 07:17:34 | Deep Dive |