|
3301
|
8.1 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: …
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24373
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3302
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager permite escalada de privilegios. Este problema afecta a …
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24373
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3303
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPVulnerability: from …
|
CWE-862
Missing Authorization
|
CVE-2026-24376
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3304
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por falta de autorización en Javier Casares WPVulnerability wpvulnerability permite la explotación de niveles de seguridad de control de acceso mal configurados. Este problema afecta a…
|
CWE-862
Missing Authorization
|
CVE-2026-24376
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3305
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through <= 4.2.8.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24378
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3306
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Metagauss EventPrime eventprime-event-calendar-management permite la inyección de objetos. Este problema afecta a EventPrime: desde n/a has…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24378
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3307
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in wproyal News Magazine X news-magazine-x allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Magazine X: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2026-24382
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3308
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en wproyal News Magazine X news-magazine-x permite explotar niveles de seguridad de control de acceso incorrectamente configurados. Este problema afecta a News…
|
CWE-862
Missing Authorization
|
CVE-2026-24382
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3309
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeMakers Car Dealer cardealer allows Reflected XSS.This issue affects Car Dealer: from n/a thr…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24391
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3310
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeMakers Car Dealer cardealer permite XSS Reflejado. Este problema afecta a …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24391
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3311
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Server Side Request Forgery.This issue affects Contest Gallery: …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24964
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3312
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de falsificación de petición del lado del servidor (SSRF) en Wasiliy Strecker / desarrollador de ContestGallery Contest Gallery contest-gallery permite la falsificación de petición del…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24964
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3313
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a through <= 7.1.0.30.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24968
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3314
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Xagio SEO Xagio SEO xagio-seo permite la escalada de privilegios. Este problema afecta a Xagio SEO: desde n/a hasta <= 7.1.0.30.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24968
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3315
|
7.7 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Instant VA instantva allows Path Traversal.This issue affects Instant VA: from n/a throu…
|
CWE-22
Path Traversal
|
CVE-2026-24969
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3316
|
7.7 |
HIGH
Network
|
-
|
-
|
Limitación Inadecuada de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') vulnerabilidad en designingmedia Instant VA instantva permite Salto de Ruta. Este problema afecta a Instant VA…
|
CWE-22
Path Traversal
|
CVE-2026-24969
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3317
|
7.7 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in designingmedia Energox energox allows Path Traversal.This issue affects Energox: from n/a through <= 1.…
|
CWE-22
Path Traversal
|
CVE-2026-24970
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3318
|
7.7 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en designingmedia Energox energox permite Salto de Ruta. Este problema afecta a Energox: des…
|
CWE-22
Path Traversal
|
CVE-2026-24970
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3319
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24971
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3320
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación de Privilegios Incorrecta en Elated-Themes Search & Go searchgo permite la escalada de privilegios. Este problema afecta a Search & Go: desde n/a hasta <= 2.8.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-24971
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3321
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elated Listing: from n/a th…
|
CWE-862
Missing Authorization
|
CVE-2026-24972
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3322
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Autorización faltante en Elated-Themes Elated Listing eltd-listing permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af…
|
CWE-862
Missing Authorization
|
CVE-2026-24972
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3323
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme CitiLights noo-citilights allows Reflected XSS.This issue affects CitiLights: from n/a t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24973
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3324
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme CitiLights noo-citilights permite XSS Reflejado. Este problema afecta a C…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24973
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3325
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection.This issue affects CitiLights: from n/a through <= 3.7.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24974
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3326
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialización de Datos No Confiables vulnerabilidad en NooTheme CitiLights noo-citilights permite Inyección de Objetos. Este problema afecta a CitiLights: desde n/a hasta <= 3.7.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24974
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3327
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Organici Library noo-organici-library allows Reflected XSS.This issue affects Organici L…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24975
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3328
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting') vulnerabilidad en la biblioteca NooTheme Organici noo-organici-library permite XSS reflejado. Est…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24975
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3329
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection.This issue affects Organici Library: from n/a through <= 2.1.2.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24976
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3330
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en NooTheme Organici Biblioteca noo-organici-library permite la inyección de objetos. Este problema afecta a Organici Biblioteca: desde n/a ha…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24976
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3331
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection.This issue affects Orga…
|
CWE-89
SQL Injection
|
CVE-2026-24977
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3332
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en la biblioteca Organici de NooTheme noo-organici-library permite Inyección SQL Cie…
|
CWE-89
SQL Injection
|
CVE-2026-24977
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3333
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection.This issue affects Jobica Core: from n/a through <= 1.4.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24978
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3334
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en NooTheme Jobica Core jobica-core permite la inyección de objetos. Este problema afecta a Jobica Core: desde n/a hasta <= 1.4.1.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24978
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3335
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobica Core jobica-core allows Reflected XSS.This issue affects Jobica Core: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24979
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3336
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme Jobica Core jobica-core permite XSS Reflejado. Este problema afecta a …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24979
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3337
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Visionary Core noo-visionary-core allows Reflected XSS.This issue affects Visionary Core…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24980
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3338
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en NooTheme Visionary Core noo-visionary-core permite XSS Reflejado. Este problema…
|
CWE-79
Cross-site Scripting
|
CVE-2026-24980
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3339
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection.This issue affects Visionary Core: from n/a through <= 1.4.9.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24981
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3340
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en NooTheme Visionary Core noo-visionary-core permite la inyección de objetos. Este problema afecta a Visionary Core: desde n/a hasta <= 1.…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24981
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3341
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24983
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3342
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en UpSolution UpSolution Core us-core permite XSS Reflejado. Este problema afecta …
|
CWE-79
Cross-site Scripting
|
CVE-2026-24983
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3343
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2026-24987
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3344
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en activity-log.com WP System Log winterlock permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema af…
|
CWE-862
Missing Authorization
|
CVE-2026-24987
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3345
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliates Pro: from n/a through < 11.4.0.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24989
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3346
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en FantasticPlugins SUMO Affiliates Pro affs permite la inyección de objetos. Este problema afecta a SUMO Affiliates Pro: desde n/a hasta <…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24989
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3347
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-reporting-statis…
|
CWE-89
SQL Injection
|
CVE-2026-24993
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3348
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') vulnerabilidad en WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-rep…
|
CWE-89
SQL Injection
|
CVE-2026-24993
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3349
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.…
|
CWE-94
Code Injection
|
CVE-2026-25001
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3350
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado de la generación de código ('Inyección de Código') en Saad Iqbal Post Snippets post-snippets permite la Inclusión Remota de Código. Este problema afecta a Post Sn…
|
CWE-94
Code Injection
|
CVE-2026-25001
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|