All coverage
CVE-2026-65443 - WordPress BackWPup plugin CVE ID : CVE-2026-65443 Published : July 27, 2026, 11:16 p.m. | 40 minutes ago Description : Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. Severity: 7.1 | HIGH Visit the link for more details... Unauthenticated Cross Site Scripting (XSS) in BackWPup
CVE-2026-14870 - Database for Contact Form 7, WPforms, Elementor forms CVE ID : CVE-2026-14870 Published : July 28, 2026, 6 a.m. | 1 hour, 25 minutes ago Description : The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not proper... The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape
CVE-2026-17528 - nice-select2 Cross-site Scripting Vulnerability CVE ID : CVE-2026-17528 Published : July 28, 2026, 6:16 a.m. | 1 hour, 8 minutes ago Description : Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the elem... Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker c
CVE-2026-66919 - Stored DOM-Based Cross-Site Scripting in Node Modal Headers CVE ID : CVE-2026-66919 Published : July 28, 2026, 1:19 p.m. | 1 hour, 21 minutes ago Description : Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. No... Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions orig
The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. https:// thehackernews.com/2026/07/russ ian-hackers-exploit-microsoft-owa.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33l5