|
2951
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4075
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2952
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin BWL Advanced FAQ Manager Lite para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'baf_sbox' en todas las versiones hasta la 1.1.1 inclusive. Esto se debe …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4075
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2953
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4335
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2954
|
5.4 |
MEDIUM
Network
|
-
|
-
|
El plugin ShortPixel Image Optimizer para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del post_title del adjunto en todas las versiones hasta la 6.4.3, inclusive. Esto se debe …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4335
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2955
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql inj…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2956
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una falla en SourceCodester Malawi Online Market 1.0. El elemento afectado es una función desconocida del archivo /display.PHP. La ejecución de una manipulación del argumento ID pued…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2957
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argum…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2958
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en SourceCodester Food Ordering System 1.0. Esto afecta una función desconocida del archivo /purchase.PHP del componente Gestor de Parámetros. La manipulación de…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2959
|
8.8 |
HIGH
Network
|
-
|
-
|
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objec…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2960
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Amelia Booking para WordPress es vulnerable a Referencias Directas Inseguras a Objetos en versiones hasta la 9.1.2, inclusive. Esto se debe a que el plugin proporciona acceso controlado por…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2961
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2962
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Simple Download Counter para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del shortcode 'sdc_menu' en todas las versiones hasta la 2.3, inclusive. Esto se debe a una s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2963
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the conne…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2964
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all vers…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2965
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El fragmento DSGVO para Leaflet Map y su plugin Extensions para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los shortcodes 'leafext-cookie-time' y 'leafext-delete-cookie' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2966
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin FormLift for Infusionsoft Web Forms para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 7.5.21, inclusive. Esto se debe a la falta de comprobaciones de c…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2967
|
7.2 |
HIGH
Network
|
-
|
-
|
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2968
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Blackhole for Bad Bots para WordPress es vulnerable a cross-site scripting almacenado a través del encabezado HTTP User-Agent en todas las versiones hasta la 3.8 inclusive. Esto se debe a u…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2969
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2970
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Blog2Social: Social Media Auto Post & Scheduler para WordPress es vulnerable a la pérdida de datos no autorizada en todas las versiones hasta la 8.8.2, inclusive. Esto se debe a que la …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2971
|
8.8 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Perf…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2972
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2973
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en el sistema de pedidos de comida en línea code-projects 1.0. Esto afecta una parte desconocida del archivo form/cart.PHP del componente Módulo de Carrito de Compras…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2974
|
8.8 |
HIGH
Network
|
-
|
-
|
Se ha descubierto una vulnerabilidad de seguridad en Netcore Power 15AX hasta la versión 3.0.0.6938. Afectada por este problema es la función setTools del archivo /bin/netis.cgi del componente Diagno…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2975
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Para…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2976
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Enrollment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /sms/grades/index.php?view=edit&id=1 del …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2977
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin.php of the component Admin Login Module. The manipulation …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4844
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2978
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Online Food Ordering System 1.0. Este problema afecta algún procesamiento desconocido del archivo /admin.php del componente Módulo de Inicio de Sesió…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4844
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2979
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic erro…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1206
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2980
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Elementor Website Builder para WordPress es vulnerable a una Autorización Incorrecta que conduce a la Exposición de Información Sensible en todas las versiones hasta la 3.35.7, inclusive. E…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1206
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2981
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. I…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4845
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2982
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado un fallo en dameng100 muucmf 1.9.5.20260309. Afecta a una función desconocida del archivo /admin/Member/index.html. Esta manipulación del argumento Search causa cross-site scripting.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4845
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2983
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the file channel/admin.Account/autoReply.html. Such manipulation of the argument keyw…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4846
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2984
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en dameng100 muucmf 1.9.5.20260309. El elemento afectado es una función desconocida del archivo channel/admin.Account/autoReply.html. Dicha manipulación del argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4846
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2985
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results i…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4847
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2986
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se encontró una vulnerabilidad en dameng100 muucmf 1.9.5.20260309. El elemento afectado es una función desconocida del archivo /admin/config/list.html. La manipulación del argumento Name resulta en c…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4847
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2987
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/extend/list.html. Executing a manipulation of the argument Name can lead to cros…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4848
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2988
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue determinada en dameng100 muucmf 1.9.5.20260309. Esto afecta una función desconocida del archivo /admin/extend/list.html. Ejecutar una manipulación del argumento Name puede llev…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4848
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2989
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/Redis…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2026-4860
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2990
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file /goform/formConfigDnsFilterGlobal of the component Paramet…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-4862
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2991
|
7.3 |
HIGH
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en 648540858 wvp-GB28181-pro hasta 2.7.4. Esto afecta a la función GenericFastJsonRedisSerializer del archivo src/main/java/com/genersoft/iot/vmp/conf/redis…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2026-4860
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2992
|
8.8 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en UTT HiPER 1250GW hasta 3.2.7-210907-180535. Este problema afecta a la función strcpy del archivo /goform/formConfigDnsFilterGlobal del componente …
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-4862
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2993
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /admin/mod_amenities/index.php?view=add. This manipulation of…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4875
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2994
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Se determinó una vulnerabilidad en itsourcecode Free Hotel Reservation System 1.0. El elemento afectado es una función desconocida del archivo /admin/mod_amenities/index.PHP?view=add. Esta manipulaci…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4875
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2995
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.6. This is due to missing nonce validation on the 'save_options' funct…
|
CWE-352
Origin Validation Error
|
CVE-2026-1032
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2996
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Conditional Menus para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.2.6, inclusive. Esto se debe a la falta de validación de n…
|
CWE-352
Origin Validation Error
|
CVE-2026-1032
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2997
|
7.2 |
HIGH
Network
|
-
|
-
|
The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2231
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2998
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Fluent Booking para WordPress es vulnerable a cross-site scripting almacenado a través de múltiples parámetros en todas las versiones hasta la 2.0.01, inclusive, debido a una sanitización d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2231
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2999
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulatio…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4876
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3000
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en itsourcecode Free Hotel Reservation System 1.0. El elemento impactado es una función desconocida del archivo /admin/mod_amenities/index.php?view=editpic. Tal ma…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4876
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|