VulnSea

radykal has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.2 (high). The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
—
Last 90 days
3 prev 0

Weakness classes

Products

  • Fancy Product Designer 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

radykal vulnerabilities

CVEs affecting radykal, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-84280High· 7.2
today

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output e…

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output e…

▾ Twilightradykal · Fancy Product DesignerEPSS 0.27%via NVD
CVE-2026-84281High· 7.2
today

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output …

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output …

▾ Twilightradykal · Fancy Product Designervia NVD
CVE-2026-84279High· 7.2
today

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping

The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This m…

▾ Twilightradykal · Fancy Product DesignerEPSS 0.19%via NVD
radykal vulnerabilities (CVEs) · VulnSea