|
1251
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Database for Contact Form 7, WPforms, Elementor forms para WordPress es vulnerable a acceso no autorizado de datos debido a una comprobación de capacidad faltante en la función entries_shor…
|
CWE-862
Missing Authorization
|
CVE-2026-3831
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1252
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en gougucms 4.08.18. Esto afecta a la función reg_submit del archivo gougucms-master\app\home\controller\Login.php del componente Gestor de Registro de Usuario. Di…
|
CWE-913 CWE-915
Improper Control of Dynamically-Managed Code Resources Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-5248
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1253
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulatio…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5249
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1254
|
3.5 |
LOW
Network
|
-
|
-
|
Se encontró una vulnerabilidad en gougucms 4.08.18. Esto afecta una función desconocida del archivo \gougucms-master\app\admin\view\user\record.html del componente Record Endpoint. Realizar una manip…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5249
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1255
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulation of the argument is…
|
CWE-913 CWE-915
Improper Control of Dynamically-Managed Code Resources Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-5251
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1256
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en z-9527 admin 1.0/2.0. Esto afecta una función desconocida del archivo /servidor/routes/user.js del componente User Update Endpoint. Dicha manipulación del argum…
|
CWE-913 CWE-915
Improper Control of Dynamically-Managed Code Resources Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-5251
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1257
|
3.5 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in z-9527 admin 1.0/2.0. Affected is an unknown function of the file /server/routes/message.js of the component Message Create Endpoint. Performing a manipulation …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5252
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1258
|
3.5 |
LOW
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en z-9527 admin 1.0/2.0. Afectada es una función desconocida del archivo /servidor/routes/message.js del componente Message Create Endpoint. Realizar una ma…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5252
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1259
|
3.5 |
LOW
Network
|
-
|
-
|
A weakness has been identified in bufanyun HotGo 1.0/2.0. Affected by this vulnerability is an unknown functionality of the file /web/src/layout/components/Header/MessageList.vue of the component edi…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5253
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1260
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in welovemedia FFmate up to 2.0.15. Affected by this issue is some unknown functionality of the file /ui/app/components/AppJsonTreeView.vue of the component…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5254
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1261
|
3.5 |
LOW
Network
|
-
|
-
|
Se ha identificado una debilidad en bufanyun HotGo 1.0/2.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /web/src/layout/components/Header/MessageList.vue del compone…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5253
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1262
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/file_manager.py of the component File Manager. Performing a manipulation of the…
|
CWE-22
Path Traversal
|
CVE-2026-5258
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1263
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the file frostmourne-monitor/src/main/java/com/autohome/frostmourne/monitor/contro…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5259
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1264
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uploadFileToIIS of the file /Base/BaseHandler.ashx. The manipulation of the argumen…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5261
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1265
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a man…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-1879
|
2026-04-25 03:12 |
2026-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1266
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to deni…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-5313
|
2026-04-25 03:12 |
2026-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1267
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The King Addons for Elementor plugin for WordPress is vulnerable to multiple Contributor+ DOM-Based Stored Cross-Site Scripting vulnerabilities in all versions up to, and including, 51.1.38. This is …
|
CWE-79
Cross-site Scripting
|
CVE-2025-13535
|
2026-04-25 03:12 |
2026-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1268
|
2.5 |
LOW
Local
|
-
|
-
|
A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the file IperiusAccounts.ini. Such manipulation leads to use of hard-coded cryptograph…
|
CWE-320 CWE-321
Key Management Errors Use of Hard-coded Cryptographic Key
|
CVE-2026-5310
|
2026-04-25 03:12 |
2026-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1269
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. This manipulation causes server-side request forgery. The attack is possible to …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5126
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1270
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en SourceCodester RSS Feed Parser 1.0. Este problema afecta a la función file_get_contents. Esta manipulación provoca falsificación de petición del lado del servid…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5126
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1271
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-website. The manipulation of the argument Website res…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5147
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1272
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido descubierta en YunaiV yudao-cloud hasta 2026.01. Esto afecta una parte desconocida del archivo /admin-api/system/tenant/get-by-website. La manipulación del arg…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5147
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1273
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_process.execSync of the file src/server.ts. The manipulation of the argument gi…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5125
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1274
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Una vulnerabilidad fue detectada en raine consult-llm-mcp hasta 2.5.3. Afectada por esta vulnerabilidad es la función child_process.execSync del archivo src/server.ts. La manipulación del argumento g…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5125
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1275
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file /admin-api/system/mail-log/page. This manipulation of the argument toMail cause…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5148
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1276
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en YunaiV yudao-cloud hasta 2026.01. Esta vulnerabilidad afecta código desconocido del archivo /admin-api/system/mail-log/page. Esta manipulación del argumento toMail…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5148
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1277
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewin_costumer.php of the component Parameter Handler. Such…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5150
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1278
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha detectado una vulnerabilidad de seguridad en code-projects Accounting System 1.0. Este problema afecta a un procesamiento desconocido del archivo /viewin_costumer.php del componente Gestor de P…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5150
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1279
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is …
|
CWE-94
Code Injection
|
CVE-2026-4257
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1280
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the ar…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5157
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1281
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en code-projects Online Food Ordering System 1.0. Afecta a una función desconocida del archivo /form/order.php del componente Order Module. Dicha manipulación del …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5157
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1282
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function i…
|
CWE-285
Improper Authorization
|
CVE-2026-1710
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1283
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin WooPayments: Pagos Integrados de WooCommerce para WordPress es vulnerable a la modificación no autorizada de datos debido a una comprobación de capacidad faltante en la función 'save_upe_ap…
|
CWE-285
Improper Authorization
|
CVE-2026-1710
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1284
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Contact Form by Supsystic para WordPress es vulnerable a la inyección de plantillas del lado del servidor (SSTI) lo que lleva a la ejecución remota de código (RCE) en todas las versiones ha…
|
CWE-94
Code Injection
|
CVE-2026-4257
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1285
|
8.8 |
HIGH
Network
|
-
|
-
|
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepting the wp_debug_trou…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2026-5130
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1286
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Debugger & Troubleshooter para WordPress era vulnerable a una escalada de privilegios no autenticada en versiones hasta la 1.3.2 inclusive. Esto se debía a que el plugin aceptaba el val…
|
CWE-565
Reliance on Cookies without Validation and Integrity Checking
|
CVE-2026-5130
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1287
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_f…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1288
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Everest Forms Pro para WordPress es vulnerable a ejecución remota de código a través de inyección de código PHP en todas las versiones hasta la 1.9.12, inclusive. Esto se debe a que la func…
|
CWE-94
Code Injection
|
CVE-2026-3300
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1289
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-1797
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1290
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Appointment Booking and Scheduler Plugin – Truebooker para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 1.1.4, inclusive, a través de los …
|
CWE-862
Missing Authorization
|
CVE-2026-1797
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1291
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4146
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1292
|
7.5 |
HIGH
Network
|
-
|
-
|
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmt…
|
CWE-200
Information Exposure
|
CVE-2026-4020
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1293
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin Gravity SMTP para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 2.1.4, inclusive. Esto se debe a un endpoint de la API REST registrado en /…
|
CWE-200
Information Exposure
|
CVE-2026-4020
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1294
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Loco Translate para WordPress es vulnerable a cross-site scripting reflejado a través del parámetro 'update_href' en todas las versiones hasta la 2.8.2, inclusive, debido a una sanitización…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4146
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1295
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of the file /admin/login.php. The manipulation of the argument Username results in s…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5179
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1296
|
7.3 |
HIGH
Network
|
-
|
-
|
Se detectó una vulnerabilidad en SourceCodester Simple Doctors Appointment System 1.0. Esto afecta una parte desconocida del archivo /admin/login.php. La manipulación del argumento Username resulta e…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5179
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1297
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=login2. This manipulation of the argument ema…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5180
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1298
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una falla en SourceCodester Simple Doctors Appointment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /admin/ajax.PHP?action=login2. Esta manipulación del argu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5180
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1299
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some unknown processing of the file /doctors_appointment/admin/ajax.php?action=save_ca…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5181
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1300
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en SourceCodester Simple Doctors Appointment System hasta 1.0. Este problema afecta a algún procesamiento desconocido del archivo /doctors_appointment/admin/ajax…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5181
|
2026-04-25 03:11 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|