| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2020-36940 | Easy CD & DVD Cover Creator 4.13 - Denial of Service | Tucows | Easy CD & DVD Cover Creator | Critical | 9.8 | 2026-01-27 15:23:48 | Deep Dive |
| CVE-2026-24617 | WordPress Easy Modal plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability | Daniel Iser | Easy Modal | 中危 | - | 2026-01-23 14:29:06 | Deep Dive |
| CVE-2025-15522 | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | uncannyowl | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin | Medium | 6.4 | 2026-01-23 04:34:58 | Deep Dive |
| CVE-2026-22472 | WordPress Easy Form Builder plugin <= 3.9.6 - Broken Access Control vulnerability | hassantafreshi | Easy Form Builder | Medium | 4.3 | 2026-01-22 16:52:42 | Deep Dive |
| CVE-2025-68839 | WordPress Easy Theme Options plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | Remi Corson | Easy Theme Options | - | - | 2026-01-22 16:52:09 | Deep Dive |
| CVE-2025-68072 | WordPress Easy Property Listings plugin <= 3.5.20 - Broken Access Control vulnerability | Merv Barrett | Easy Property Listings | - | - | 2026-01-22 16:52:07 | Deep Dive |
| CVE-2026-22082 | Insecure Session ID Management Vulnerability in Tenda Wireless Routers | Tenda | 300Mbps Wireless Router F3 and N300 Easy Setup Router | 中危 | - | 2026-01-09 11:24:54 | Deep Dive |
| CVE-2026-22081 | Cookie without HTTPOnly Flag Vulnerability in Tenda Wireless Routers | Tenda | 300Mbps Wireless Router F3 and N300 Easy Setup Router | 中危 | - | 2026-01-09 11:16:22 | Deep Dive |
| CVE-2026-22080 | Insecure Transmission Vulnerability in Tenda Wireless Routers | Tenda | 300Mbps Wireless Router F3 and N300 Easy Setup Router | 中危 | - | 2026-01-09 11:05:07 | Deep Dive |
| CVE-2026-22079 | Cleartext Transmission Vulnerability in Tenda Wireless Routers | Tenda | 300Mbps Wireless Router F3 and N300 Easy Setup Router | 中危 | - | 2026-01-09 11:02:51 | Deep Dive |
| CVE-2025-69169 | WordPress Easy Media Download plugin <= 1.1.11 - CSS Injection vulnerability | Noor Alam | Easy Media Download | Medium | 5.4 | 2026-01-08 09:17:55 | Deep Dive |
| CVE-2025-22715 | WordPress WP Attractive Donations System - Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion vulnerability | loopus | WP Attractive Donations System - Easy Stripe & Paypal donations | High | 7.5 | 2026-01-08 09:17:40 | Deep Dive |
| CVE-2025-14147 | Easy GitHub Gist Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute | corsonr | Easy GitHub Gist Shortcodes | Medium | 6.4 | 2026-01-07 09:21:03 | Deep Dive |
| CVE-2025-9637 | Quiz and Survey Master (QSM) <= 10.3.1 - Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-01-06 09:20:59 | Deep Dive |
| CVE-2025-9318 | Quiz and Survey Master (QSM) <= 10.3.1 - Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 6.5 | 2026-01-06 09:20:59 | Deep Dive |
| CVE-2025-9294 | Quiz And Survey Master <= 10.3.1 - Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion | expresstech | Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker | Medium | 4.3 | 2026-01-06 08:21:49 | Deep Dive |
| CVE-2025-53235 | WordPress Easy Social plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability | osuthorpe | Easy Social | High | 7.1 | 2025-12-31 20:11:26 | Deep Dive |
| CVE-2025-62078 | WordPress Easy Upload Files During Checkout plugin <= 3.0.0 - Broken Access Control vulnerability | Fahad Mahmood | Easy Upload Files During Checkout | Medium | 4.3 | 2025-12-31 16:32:01 | Deep Dive |
| CVE-2025-14783 | Easy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect | smub | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | Medium | 4.3 | 2025-12-31 06:24:43 | Deep Dive |
| CVE-2025-62112 | WordPress Import into Easy Property Listings plugin <= 2.2.1 - Cross Site Request Forgery (CSRF) vulnerability | Merv Barrett | Import into Easy Property Listings | Medium | 4.3 | 2025-12-30 16:21:31 | Deep Dive |