| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2019-25646 | Tabs Mail Carrier 2.5.1 Buffer Overflow via MAIL FROM | Tabs | Mail Carrier | Critical | 9.8 | 2026-03-24 11:27:17 | Deep Dive |
| CVE-2026-4202 | Broken Access Control in extension "Redirect Tab" | TYPO3 | Extension "Redirect Tabs" | - | - | 2026-03-17 08:33:41 | Deep Dive |
| CVE-2019-25364 | Win10 MailCarrier 2.51 - 'POP3 User' Remote Buffer Overflow | TABS Laboratories Corporation | Win10 MailCarrier | Critical | 9.8 | 2026-02-18 21:55:10 | Deep Dive |
| CVE-2025-14999 | Latest Tabs <= 1.5 - Cross-Site Request Forgery to Plugin's Settings Update | kentothemes | Latest Tabs | Medium | 4.3 | 2026-01-07 08:21:53 | Deep Dive |
| CVE-2025-14428 | My Sticky Elements <= 2.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk Lead Deletion | premio | All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements | Medium | 4.3 | 2026-01-01 16:19:31 | Deep Dive |
| CVE-2025-13088 | Category and Product Woocommerce Tabs <= 1.0 - Authenticated (Contributor+) Local File Inclusion | ikhodal | Category and Product Woocommerce Tabs | High | 8.8 | 2025-11-18 08:27:37 | Deep Dive |
| CVE-2025-11822 | WP Bootstrap Tabs <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | virtus-designs | WP Bootstrap Tabs | Medium | 6.4 | 2025-11-11 03:30:32 | Deep Dive |
| CVE-2025-58985 | WordPress Additional Custom Product Tabs for WooCommerce Plugin <= 1.7.3 - Cross Site Scripting (XSS) Vulnerability | WPFactory | Additional Custom Product Tabs for WooCommerce | Medium | 6.5 | 2025-09-09 16:33:13 | Deep Dive |
| CVE-2025-54594 | react-native-bottom-tabs: Arbitrary code execution in GitHub Actions canary workflow leads to secret exfiltration | callstackincubator | react-native-bottom-tabs | Critical | 9.1 | 2025-08-05 23:31:53 | Deep Dive |
| CVE-2025-48134 | WordPress WP Tabs plugin <= 2.2.12 - PHP Object Injection Vulnerability | ShapedPlugin LLC | WP Tabs | High | 7.2 | 2025-05-16 15:45:14 | Deep Dive |
| CVE-2025-46522 | WordPress Tabs plugin <= 4.0.3 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability | Billy Bryant | Tabs | High | 7.1 | 2025-04-24 16:08:58 | Deep Dive |
| CVE-2025-26749 | WordPress Additional Custom Product Tabs for WooCommerce plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerability | WPFactory | Additional Custom Product Tabs for WooCommerce | Medium | 6.5 | 2025-04-15 21:53:11 | Deep Dive |
| CVE-2025-32075 | IP and user agent leaks in Extension:Tabs | The Wikimedia Foundation | Mediawiki - Tabs Extension | - | - | 2025-04-11 16:22:00 | Deep Dive |
| CVE-2024-11503 | WP Tabs < 2.2.7 - Admin+ Stored XSS | Unknown | WP Tabs | 中危 | - | 2025-03-25 06:00:11 | Deep Dive |
| CVE-2024-13831 | Tabs for WooCommerce <= 1.0.0 - Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs | wpbranch | Tabs for WooCommerce | High | 7.2 | 2025-02-28 08:23:17 | Deep Dive |
| CVE-2024-12600 | Custom Product Tabs Lite for WooCommerce <= 1.9.0 - Authenticated (Shop Manager+) PHP Object Injection | skyverge | Custom Product Tabs Lite for WooCommerce | High | 7.2 | 2025-01-25 06:40:39 | Deep Dive |
| CVE-2024-13721 | Plethora Plugins Tabs + Accordions <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor | plethoraplugins | Plethora Plugins Tabs + Accordions | Medium | 6.4 | 2025-01-25 05:30:07 | Deep Dive |
| CVE-2025-24709 | WordPress Plethora Plugins Tabs + Accordions plugin <= 1.1.5 - Stored Cross Site Scripting (XSS) vulnerability | Plethora Plugins | Plethora Plugins Tabs + Accordions | Medium | 6.5 | 2025-01-24 17:25:02 | Deep Dive |
| CVE-2024-13387 | WP Responsive Tabs <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting | fahadmahmood | WP Responsive Tabs | Medium | 6.4 | 2025-01-16 09:39:14 | Deep Dive |
| CVE-2024-11606 | Tabs Shortcode <= 2.0.2 - Contributor+ XSS via Shortcode | Unknown | Tabs Shortcode | 中危 | - | 2025-01-07 06:00:04 | Deep Dive |