| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39454 | SKYSEA Client View 安全漏洞 | Sky Co.,LTD. | SKYSEA Client View | - | - | 2026-04-20 08:04:57 | Deep Dive |
| CVE-2026-2396 | List View Google Calendar <= 7.4.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via Event Description | kimipooh | List View Google Calendar | Medium | 4.4 | 2026-04-14 23:26:07 | Deep Dive |
| CVE-2026-25465 | WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Cross Site Scripting (XSS) vulnerability | codepeople | CP Multi View Event Calendar | Medium | 6.5 | 2026-03-25 16:14:52 | Deep Dive |
| CVE-2026-1640 | Taskbuilder <= 5.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation | taskbuilder | Taskbuilder – Project Management & Task Management Tool With Kanban Board | Medium | 4.3 | 2026-02-18 06:42:42 | Deep Dive |
| CVE-2026-1639 | Taskbuilder <= 5.0.2 - Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters | taskbuilder | Taskbuilder – Project Management & Task Management Tool With Kanban Board | Medium | 6.5 | 2026-02-18 05:29:17 | Deep Dive |
| CVE-2026-23754 | D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover | D-Link | D-View 8 | - | - | 2026-01-21 18:02:46 | Deep Dive |
| CVE-2026-23755 | D-Link D-View 8 Installer DLL Preloading via Uncontrolled Search Path | D-Link | D-View 8 | - | - | 2026-01-21 18:02:30 | Deep Dive |
| CVE-2026-0563 | WP Google Street View (with 360° virtual tour) & Google maps + Local SEO <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpgsv_map' Shortcode | pagup | WP Google Street View (with 360° virtual tour) & Google maps + Local SEO | Medium | 6.4 | 2026-01-09 06:34:54 | Deep Dive |
| CVE-2025-8617 | YITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode | yithemes | YITH WooCommerce Quick View | Medium | 6.4 | 2025-12-13 04:31:29 | Deep Dive |
| CVE-2025-63034 | WordPress Page View Count plugin <= 2.9.0 - Settings Change vulnerability | Steve Truman | Page View Count | Medium | 5.4 | 2025-12-09 14:52:30 | Deep Dive |
| CVE-2025-12584 | Quick View for WooCommerce <= 2.2.17 - Unauthenticated Private Product Disclosure | shapedplugin | Quick View for WooCommerce | Medium | 5.3 | 2025-11-27 09:27:49 | Deep Dive |
| CVE-2025-13084 | Opto 22 groov View Exposure of Sensitive Information Through Metadata | Opto 22 | groov View Server | High | 7.6 | 2025-11-26 17:39:38 | Deep Dive |
| CVE-2025-11808 | Shortcode for Google Street View <= 0.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | antiochinteractive | Shortcode for Google Street View | Medium | 6.4 | 2025-11-21 08:28:14 | Deep Dive |
| CVE-2025-11741 | WPC Smart Quick View for WooCommerce <= 4.2.5 - Insecure Direct Object Reference to Unauthenticated Private Product Exposure | wpclever | WPC Smart Quick View for WooCommerce | Medium | 5.3 | 2025-10-18 06:42:45 | Deep Dive |
| CVE-2025-9064 | Rockwell Automation FactoryTalk View Machine Edition Path Traversal | Rockwell Automation | FactoryTalk View Machine Edition | - | - | 2025-10-14 12:22:37 | Deep Dive |
| CVE-2025-57967 | WordPress WPB Quick View for WooCommerce plugin <= 2.1.8 - Cross Site Scripting (XSS) vulnerability | WPBean | WPB Quick View for WooCommerce | Medium | 6.5 | 2025-09-22 18:24:40 | Deep Dive |
| CVE-2025-58009 | WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Broken Access Control vulnerability | codepeople | CP Multi View Event Calendar | Low | 3.8 | 2025-09-22 18:24:10 | Deep Dive |
| CVE-2025-58228 | WordPress Quick View for WooCommerce Plugin <= 2.2.16 - Cross Site Scripting (XSS) Vulnerability | ShapedPlugin LLC | Quick View for WooCommerce | Medium | 6.5 | 2025-09-22 18:23:44 | Deep Dive |
| CVE-2025-10453 | PilotGaea Technologies|O'View MapServer - Server-Side Request Forgery | PilotGaea Technologies | O'View MapServer | Medium | 5.3 | 2025-09-15 06:06:11 | Deep Dive |
| CVE-2025-48110 | WordPress Link View plugin <= 0.8.0 - Cross Site Scripting (XSS) vulnerability | mibuthu | Link View | Medium | 6.5 | 2025-08-28 12:36:47 | Deep Dive |