|
3351
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25002
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3352
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en ThimPress LearnPress – Sepay Payment learnpress-sepay-payment permite el abuso de autenticación. Este problema afecta…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25002
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3353
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Bl…
|
CWE-89
SQL Injection
|
CVE-2026-25007
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3354
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-ele…
|
CWE-89
SQL Injection
|
CVE-2026-25007
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3355
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Zone: from n/a thro…
|
CWE-862
Missing Authorization
|
CVE-2026-25009
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3356
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en raratheme Education Zone education-zone permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afec…
|
CWE-862
Missing Authorization
|
CVE-2026-25009
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3357
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25013
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3358
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en WHMCSdes Phox Hosting phox-host permite XSS Reflejado. Este problema afecta a P…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25013
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3359
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows PHP Local File Inclu…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-25017
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3360
|
8.1 |
HIGH
Network
|
-
|
-
|
La vulnerabilidad de control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión remota de ficheros PHP') en stmcan NaturaLife Extensions naturalife-ex…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-25017
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3361
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan NaturaLife Extensions naturalife-extensions allows Reflected XSS.This issue affects Natura…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25018
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3362
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en stmcan NaturaLife Extensions naturalife-extensions permite XSS Reflejado. Este …
|
CWE-79
Cross-site Scripting
|
CVE-2026-25018
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3363
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: fr…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25025
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3364
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en e4jvikwp VikRestaurants vikrestaurants permite XSS Reflejado. Este problema afe…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25025
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3365
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11.
|
CWE-862
Missing Authorization
|
CVE-2026-25026
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3366
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Autorización Faltante en RadiusTheme Team tlp-team permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados. Este problema afecta a Team: desde n/a ha…
|
CWE-862
Missing Authorization
|
CVE-2026-25026
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3367
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25029
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3368
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en park_of_ideas KIDZ kidz permite la inyección de objetos. Este problema afecta a KIDZ: desde n/a hasta <= 5.24.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25029
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3369
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through < 3.47.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25030
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3370
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en park_of_ideas Goldish goldish permite Inyección de objetos. Este problema afecta a Goldish: desde n/a hasta < 3.47.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25030
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3371
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from n/a through < 1.27.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25031
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3372
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en park_of_ideas Tasty Daily tastydaily permite la inyección de objetos. Este problema afecta a Tasty Daily: desde n/a hasta < 1.27.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25031
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3373
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.31.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25032
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3374
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en park_of_ideas Ricky ricky permite la inyección de objetos. Este problema afecta a Ricky: desde n/a hasta < 2.31.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25032
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3375
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uixthemes Motta Addons motta-addons allows Reflected XSS.This issue affects Motta Addons: from n/…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25033
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3376
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en uixthemes Motta Addons motta-addons permite XSS Reflejado. Este problema afecta…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25033
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3377
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: fr…
|
CWE-862
Missing Authorization
|
CVE-2026-25034
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3378
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Iqonic Design KiviCare kivicare-clinic-management-system permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. E…
|
CWE-862
Missing Authorization
|
CVE-2026-25034
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3379
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Authentication Abuse.This issue affects Co…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25035
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3380
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Omisión de autenticación Usando una Ruta o Canal Alternativo vulnerabilidad en Wasiliy Strecker / el desarrollador de ContestGallery Contest Gallery contest-gallery permite el Abuso de Autenticación.…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25035
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3381
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Jaroti jaroti allows Reflected XSS.This issue affects Jaroti: from n/a through < 1.4.8.
|
CWE-79
Cross-site Scripting
|
CVE-2026-25304
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3382
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en skygroup Jaroti jaroti permite XSS Reflejado. Este problema afecta a Jaroti:…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25304
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3383
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25306
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3384
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') en el plugin 8theme XStore Core et-core-plugin permite XSS Reflejado. Este problem…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25306
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3385
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress A…
|
CWE-862
Missing Authorization
|
CVE-2026-25309
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3386
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Autorización Faltante en PublishPress PublishPress Authors publishpress-authors permite Explotar Niveles de Seguridad de Control de Acceso Configurados Incorrectamente. Este problem…
|
CWE-862
Missing Authorization
|
CVE-2026-25309
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3387
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels…
|
CWE-862
Missing Authorization
|
CVE-2026-25317
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3388
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes permite la explotación de niveles de seguridad de control de ac…
|
CWE-862
Missing Authorization
|
CVE-2026-25317
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3389
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
|
CWE-862
Missing Authorization
|
CVE-2026-25327
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3390
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de Autorización Faltante en Rustaurius Five Star Restaurant Reservations restaurant-reservations permite Explotar Niveles de Seguridad de Control de Acceso Incorrectamente Configurados…
|
CWE-862
Missing Authorization
|
CVE-2026-25327
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3391
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traver…
|
CWE-22
Path Traversal
|
CVE-2026-25328
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3392
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') vulnerabilidad en add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce permite…
|
CWE-22
Path Traversal
|
CVE-2026-25328
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3393
|
8.1 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a throu…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-25334
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3394
|
8.1 |
HIGH
Network
|
-
|
-
|
La vulnerabilidad de Asignación Incorrecta de Privilegios en wordpresschef Salon Booking System Pro salon-booking-plugin-pro permite la escalada de privilegios. Este problema afecta a Salon Booking S…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-25334
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3395
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms:…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-25339
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3396
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Inserción de Información Sensible en Datos Enviados vulnerabilidad en Formulario de Contacto de Syed Balkhi de WPForms wpforms-lite permite Recuperar Datos Sensibles Incrustados. Este problema afecta…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-25339
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3397
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from…
|
CWE-89
SQL Injection
|
CVE-2026-25340
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3398
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en NooTheme Jobmonster noo-jobmonster permite Inyección SQL Ciega. Este problema afe…
|
CWE-89
SQL Injection
|
CVE-2026-25340
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3399
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a throu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25341
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3400
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en RSJoomla! RSFirewall! rsfirewall permite XSS Almacenado. Este problema afecta a…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25341
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|