| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-4335 | ShortPixel Image Optimizer <= 6.4.3 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title | shortpixel | ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF | Medium | 5.4 | 2026-03-26 02:25:20 | Deep Dive |
| CVE-2026-24141 | NVIDIA Model Optimizer 代码问题漏洞 | NVIDIA | NVIDIA Model Optimizer | High | 7.8 | 2026-03-24 20:26:52 | Deep Dive |
| CVE-2026-25906 | Dell Optimizer 后置链接漏洞 | Dell | Optimizer | High | 7.3 | 2026-03-03 20:55:41 | Deep Dive |
| CVE-2026-25387 | WordPress Image Optimizer by Elementor plugin <= 1.7.1 - Broken Access Control vulnerability | Elementor | Image Optimizer by Elementor | Medium | 4.3 | 2026-02-19 08:27:02 | Deep Dive |
| CVE-2026-1319 | Robin Image Optimizer <= 2.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via Image Alternative Text Field | themeisle | Robin Image Optimizer – Unlimited Image Optimization & WebP Converter | Medium | 6.4 | 2026-02-05 08:25:43 | Deep Dive |
| CVE-2026-1246 | ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter | shortpixel | ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF | Medium | 4.9 | 2026-02-05 06:47:41 | Deep Dive |
| CVE-2025-14482 | Crush.pics Image Optimizer <= 1.8.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update | crushpics | Crush.pics Image Optimizer – Image Compression and Optimization | Medium | 4.3 | 2026-01-14 05:28:09 | Deep Dive |
| CVE-2025-15019 | BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | pagup | Bulk Auto Image Alt Text (Alt tag, Alt attribute) optimizer (image SEO) | Medium | 6.4 | 2026-01-09 06:34:52 | Deep Dive |
| CVE-2025-68861 | WordPress Plugin Optimizer plugin <= 1.3.7 - Broken Access Control vulnerability | pluginoptimizer | Plugin Optimizer | High | 7.1 | 2025-12-29 17:23:09 | Deep Dive |
| CVE-2025-13377 | 10Web Booster <= 2.32.7 - Authenticated (Subscriber+) Arbitrary Folder Deletion via two_clear_page_cache | 10web | 10Web Booster – Website speed optimization, Cache & Page Speed optimizer | Critical | 9.6 | 2025-12-06 06:39:09 | Deep Dive |
| CVE-2025-12190 | Image Optimizer by wps.sk <= 1.2.0 - Cross-Site Request Forgery to Bulk Image Optimization | duddi | Image Optimizer by wps.sk | Medium | 4.3 | 2025-12-05 05:31:29 | Deep Dive |
| CVE-2025-12015 | Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed <= 2.0.0 - Missing Authorization to Authenticated (Subscriber+) Afosto Disconnect | sanderkah | Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed | Medium | 4.3 | 2025-11-13 08:27:46 | Deep Dive |
| CVE-2025-10714 | AXIS OS 安全漏洞 | Axis Communications AB | AXIS Optimizer | High | 8.4 | 2025-11-11 07:16:05 | Deep Dive |
| CVE-2025-60074 | WordPress Lazy Load Optimizer plugin <= 1.4.7 - Local File Inclusion vulnerability | Processby | Lazy Load Optimizer | High | 7.5 | 2025-11-06 15:54:44 | Deep Dive |
| CVE-2025-12014 | NGINX Cache Optimizer <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Dynamic Caching Exclusion Update | getclouder | NGINX Cache Optimizer | Medium | 4.3 | 2025-10-24 08:24:01 | Deep Dive |
| CVE-2025-11378 | ShortPixel Image Optimizer <= 6.3.4 - Authenticated (Contributor+) Settings Import/Export | shortpixel | ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF | Medium | 5.4 | 2025-10-18 03:33:23 | Deep Dive |
| CVE-2025-11163 | SmartCrawl SEO checker, analyzer & optimizer <= 3.14.3 - Missing Authorization to Plugin Settings Update | wpmudev | SmartCrawl SEO checker, analyzer & optimizer | Medium | 4.3 | 2025-09-30 05:28:53 | Deep Dive |
| CVE-2025-53219 | WordPress WP-Database-Optimizer-Tools Plugin <= 0.2 - Cross Site Request Forgery (CSRF) Vulnerability | pl4g4 | WP-Database-Optimizer-Tools | Medium | 5.4 | 2025-08-14 18:22:02 | Deep Dive |
| CVE-2025-53314 | WordPress WP Optimizer plugin <= 2.5.0 - Cross Site Request Forgery (CSRF) vulnerability | sh1zen | WP Optimizer | Critical | 9.6 | 2025-06-27 13:21:36 | Deep Dive |
| CVE-2025-4217 | WP YouTube Video Optimizer <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | measuremarketing | WP YouTube Video Optimizer | Medium | 6.4 | 2025-05-21 09:21:51 | Deep Dive |