We get it — your site sits on a stack everyone else is trying to break. WebVuln™ is a working index of known web vulnerabilities for those platforms.
Total CVEs
7114
Stacks with data
16
High / critical
2983
Newest published
2026-08-12
| CVE | Stack | Summary | Severity | CVSS | Published | Detail |
|---|---|---|---|---|---|---|
| CVE-2026-18961 | WordPress | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authenticati… | HIGH | 8.1 | Details | |
| CVE-2026-71290 | Apache HTTP Server | Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting h… | — | — | Details | |
| CVE-2026-63177 | nginx | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua l… | HIGH | 7.1 | Details | |
| CVE-2026-55676 | PHP | Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/sub… | HIGH | 8.8 | Details | |
| CVE-2026-55676 | nginx | Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/sub… | HIGH | 8.8 | Details | |
| CVE-2026-15606 | WordPress | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. T… | HIGH | 8.8 | Details | |
| CVE-2026-73231 | Node.js | Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/help… | HIGH | 7.8 | Details | |
| CVE-2026-73229 | Django | Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/ren… | MEDIUM | 4.3 | Details | |
| CVE-2026-19091 | WordPress | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file dele… | HIGH | 8.1 | Details | |
| CVE-2026-16230 | WordPress | The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delet… | CRITICAL | 9.8 | Details | |
| CVE-2026-13457 | WordPress | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and… | HIGH | 7.5 | Details | |
| CVE-2026-73228 | Django | Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/r… | MEDIUM | 5.3 | Details | |
| CVE-2026-73222 | Node.js | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by … | HIGH | 8.8 | Details | |
| CVE-2026-69117 | Express | NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inj… | MEDIUM | 6.5 | Details | |
| CVE-2026-69117 | Django | NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inj… | MEDIUM | 6.5 | Details | |
| CVE-2026-15426 | WordPress | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to author… | HIGH | 8.8 | Details | |
| CVE-2026-73089 | Node.js | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js re… | HIGH | 7.5 | Details | |
| CVE-2026-73088 | Node.js | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeSt… | HIGH | 7.5 | Details | |
| CVE-2026-73083 | Node.js | Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled u… | — | — | Details | |
| CVE-2026-46670 | PHP | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormMana… | CRITICAL | 9.8 | Details |
WebVuln™ lists NVD records that match our curated web-stack keywords — not personalized security advice. For your own site, run WebCheck™.