|
1201
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractC…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5470
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1202
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5472
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1203
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. E…
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-5484
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1204
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() functi…
|
CWE-862
Missing Authorization
|
CVE-2026-3571
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1205
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2924
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1206
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Box widget in versions up to, and including, 1.4.24 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2949
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1207
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Widget's 'onClick Event' setting in all versions up to, and including, 1…
|
CWE-79
Cross-site Scripting
|
CVE-2025-13368
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1208
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user descr…
|
CWE-79
Cross-site Scripting
|
CVE-2025-15064
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1209
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and including, 5.2.4 due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-0552
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1210
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter in all versions up to, and including, 1.7.1049 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2026-0664
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1211
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.7. This is due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2026-0737
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1212
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the su_carousel shortcode in all versions up to, and including, 7.4.8. This is due…
|
CWE-79
Cross-site Scripting
|
CVE-2026-0738
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1213
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2600
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1214
|
8.1 |
HIGH
Network
|
-
|
-
|
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4896
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1215
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, …
|
CWE-79
Cross-site Scripting
|
CVE-2026-2437
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1216
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not pr…
|
CWE-862
Missing Authorization
|
CVE-2026-2826
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1217
|
7.1 |
HIGH
Network
|
-
|
-
|
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass …
|
CWE-862
Missing Authorization
|
CVE-2026-3445
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1218
|
7.2 |
HIGH
Network
|
-
|
-
|
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' parameter keys in all versions up to, and including, 1.7.9 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2026-5425
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1219
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2025-14938
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1220
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpf_optin_form' shortcode in all v…
|
CWE-79
Cross-site Scripting
|
CVE-2026-0626
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1221
|
7.5 |
HIGH
Network
|
-
|
-
|
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containin…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-1233
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1222
|
7.2 |
HIGH
Network
|
-
|
-
|
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2936
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1223
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all ve…
|
CWE-94
Code Injection
|
CVE-2026-3309
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1224
|
8.8 |
HIGH
Network
|
-
|
-
|
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4.16. This is due to a missing file name/path validation against path traversal …
|
CWE-22
Path Traversal
|
CVE-2026-3666
|
2026-04-25 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1225
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown part of the component HTTP Interface. Such manipulation leads to os command inject…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5528
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1226
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipul…
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-5529
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1227
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in Ollama up to 18.1. This issue affects some unknown processing of the file server/download.go of the component Model Pull API. Executing a manipulation can lead to server-side…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5530
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1228
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. Th…
|
CWE-312 CWE-313
Cleartext Storage of Sensitive Information Cleartext Storage in a File or on Disk
|
CVE-2026-5531
|
2026-04-25 03:13 |
2026-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1229
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5198
|
2026-04-25 03:12 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1230
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library modules/UserGuide/lib/class.UserGuideImporterExporter.php of the component UserG…
|
CWE-22
Path Traversal
|
CVE-2026-5203
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1231
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such man…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5205
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1232
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argumen…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5206
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1233
|
2.4 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipula…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5209
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1234
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a manipulation of the argument page results in file inclusion. Remote exploitatio…
|
CWE-73
External Control of File Name or Path
|
CVE-2026-5210
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1235
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'max_width' attribute of the `su_box` shortcode in all versions up to, and inc…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2480
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1236
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Shortcodes Plugin — Shortcodes Ultimate para WordPress es vulnerable a cross-site scripting almacenado a través del atributo 'max_width' del shortcode 'su_box' en todas las versiones has…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2480
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1237
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was determined in Axiomatic Bento4 up to 1.6.0-641. This impacts the function AP4_BitReader::ReadCache of the file Ap4Dac4Atom.cpp of the component MP4 File Parser. This manipulation …
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5235
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1238
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Una vulnerabilidad fue determinada en Axiomatic Bento4 hasta 1.6.0-641. Esto afecta la función AP4_BitReader::ReadCache del archivo Ap4Dac4Atom.cpp del componente MP4 File Parser. Esta manipulación c…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5235
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1239
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was identified in Axiomatic Bento4 up to 1.6.0-641. Affected is the function AP4_BitReader::SkipBits of the file Ap4Dac4Atom.cpp of the component DSI v1 Parser. Such manipulation of t…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5236
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1240
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_user.php of the component Parameter H…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5237
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1241
|
7.3 |
HIGH
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en itsourcecode Payroll Management System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /manage_user.php del componente…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5237
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1242
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. E…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5238
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1243
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Se identificó una vulnerabilidad en Axiomatic Bento4 hasta la versión 1.6.0-641. Se ve afectada la función AP4_BitReader::SkipBits del archivo Ap4Dac4Atom.cpp del componente DSI v1 Parser. Dicha mani…
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-5236
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1244
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and incl…
|
CWE-89
SQL Injection
|
CVE-2026-4668
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1245
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Booking for Appointments and Events Calendar - Amelia para WordPress es vulnerable a inyección SQL a través del parámetro `sort` en el endpoint de listado de pagos en todas las versiones ha…
|
CWE-89
SQL Injection
|
CVE-2026-4668
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1246
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en itsourcecode Payroll Management System 1.0. Este problema afecta a alguna funcionalidad desconocida del archivo /view_employee.php del componente Gestor de Parámet…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5238
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1247
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. This affects an unknown part of the file /admin_state.php. The manipulation of the argument statename leads …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5240
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1248
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en code-projects BloodBank Managing System 1.0. Esto afecta una parte desconocida del archivo /admin_state.php. La manipulación del argumento statena…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5240
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1249
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such man…
|
CWE-913 CWE-915
Improper Control of Dynamically-Managed Code Resources Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-5248
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1250
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in al…
|
CWE-862
Missing Authorization
|
CVE-2026-3831
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|