Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
news
Visual Composer LFI is CVE-2026-12227
Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.
Published 3h ago
CriticalPoC Available
CVE-2026-12227
Visual Composer unauthenticated local file inclusion
Other
Published 11d ago