|
3451
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4528
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3452
|
7.3 |
HIGH
Network
|
-
|
-
|
Se determinó una vulnerabilidad en trueleaf ApiFlow 0.9.7. El elemento afectado es la función validateUrlSecurity del archivo packages/server/src/service/proxy/http_proxy.service.ts del componente Ge…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4528
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3453
|
8.1 |
HIGH
Network
|
-
|
-
|
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' …
|
CWE-269
Improper Privilege Management
|
CVE-2026-3629
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3454
|
8.1 |
HIGH
Network
|
-
|
-
|
El plugin Importar y exportar usuarios y clientes para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta, e incluyendo, la 1.29.7. Esto se debe a que la función 'save_ext…
|
CWE-269
Improper Privilege Management
|
CVE-2026-3629
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3455
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix WARN_ON in tracing_buffers_mmap_close
When a process forks, the child process copies the parent's VMAs but the
user_…
|
CWE-617
Reachable Assertion
|
CVE-2026-23380
|
2026-04-25 01:28 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3456
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
tracing: Corrección de WARN_ON en tracing_buffers_mmap_close
Cuando un proceso hace fork, el proceso hijo copia los VMAs del pad…
|
CWE-617
Reachable Assertion
|
CVE-2026-23380
|
2026-04-25 01:28 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3457
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter in the 'tcg_select2_search_post' AJAX action in all versions up to, and includin…
|
CWE-89
SQL Injection
|
CVE-2026-2503
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3458
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin ElementCamp para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'meta_query[compare]' en la acción AJAX 'tcg_select2_search_post' en todas las versiones has…
|
CWE-89
SQL Injection
|
CVE-2026-2503
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3459
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to…
|
CWE-862
Missing Authorization
|
CVE-2026-2720
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3460
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Hr Press Lite para WordPress es vulnerable a acceso no autorizado de datos sensibles de empleados debido a una comprobación de capacidad faltante en la acción AJAX 'hrp-fetch-employees' en …
|
CWE-862
Missing Authorization
|
CVE-2026-2720
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3461
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings page handlers for…
|
CWE-352
Origin Validation Error
|
CVE-2026-2723
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3462
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Post Snippits para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.0, inclusive. Esto se debe a la falta de validación de nonce e…
|
CWE-352
Origin Validation Error
|
CVE-2026-2723
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3463
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Ricerca – advanced search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin's settings in all versions up to, and including, 1.1.12 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2837
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3464
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin de búsqueda avanzada Ricerca para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.1.12, inclusive, debido…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2837
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3465
|
8.8 |
HIGH
Network
|
-
|
-
|
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all…
|
CWE-862
Missing Authorization
|
CVE-2026-2941
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3466
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Linksy Search and Replace para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de verificación de capacidad en la función 'linksy_search_and_replace_item…
|
CWE-862
Missing Authorization
|
CVE-2026-2941
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3467
|
7.2 |
HIGH
Network
|
-
|
-
|
The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitiz…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3003
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3468
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Vagaro Booking Widget para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'vagaro_code' en todas las versiones hasta la 0.3, inclusive, debido a una saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3003
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3469
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fo…
|
CWE-352
Origin Validation Error
|
CVE-2026-3331
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3470
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Lobot Slider Administrator para WordPress es vulnerable a la falsificación de petición en sitios cruzados en versiones hasta la 0.6.0, inclusive. Esto se debe a la validación de nonce falta…
|
CWE-352
Origin Validation Error
|
CVE-2026-3331
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3471
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Xhanch - My Advanced Settings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation in the `xms_set…
|
CWE-352
Origin Validation Error
|
CVE-2026-3332
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3472
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linkgate' shortcode in all versions up to, and including, 3.6.1 due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3333
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3473
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin MinhNhut Link Gateway para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'linkgate' del plugin en todas las versiones hasta la 3.6.1, inclusive, debido a …
|
CWE-79
Cross-site Scripting
|
CVE-2026-3333
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3474
|
8.8 |
HIGH
Network
|
-
|
-
|
The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is…
|
CWE-89
SQL Injection
|
CVE-2026-3334
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3475
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Comment SPAM Wiper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' setting in all versions up to, and including, 1.2.1. This is due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3353
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3476
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Xhanch - My Advanced Settings para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.1.2, inclusive. Esto se debe a la falta de val…
|
CWE-352
Origin Validation Error
|
CVE-2026-3332
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3477
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin CMS Commander para WordPress es vulnerable a inyección SQL a través de los parámetros 'or_blogname', 'or_blogdescription' y 'or_admin_email' en todas las versiones hasta la 2.288, inclusive…
|
CWE-89
SQL Injection
|
CVE-2026-3334
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3478
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to …
|
CWE-862
Missing Authorization
|
CVE-2026-3335
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3479
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Canto para WordPress presenta una vulnerabilidad de falta de autorización en todas las versiones hasta la 3.1.1, incluida esta, a través del archivo `/wp-content/plugins/canto/includes/lib/…
|
CWE-862
Missing Authorization
|
CVE-2026-3335
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3480
|
5.5 |
MEDIUM
Network
|
-
|
-
|
The Multi Functional Flexi Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `arv_lb[message]` parameter in all versions up to, and including, 1.2 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3347
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3481
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Comment Correo no deseado Wiper para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración 'API Key' en todas las versiones hasta la 1.2.1, inclusive. Esto …
|
CWE-79
Cross-site Scripting
|
CVE-2026-3353
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3482
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Wikilookup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Popup Width' setting in all versions up to, and including, 1.1.5. This is due to insufficient input sanitizat…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3354
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3483
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Wikilookup para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración 'Popup Width' en todas las versiones hasta la 1.1.5, inclusive. Esto se debe a una san…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3354
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3484
|
5.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Multi Functional Flexi Lightbox para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro `arv_lb[message]` en todas las versiones hasta la 1.2, inclusive, debid…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3347
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3485
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2. This is due to the permission callback (update_user_wec…
|
CWE-20
Improper Input Validation
|
CVE-2026-3460
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3486
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin REST API TO MiniProgram para WordPress es vulnerable a la Referencia Directa Insegura a Objetos en todas las versiones hasta la 5.1.2, inclusive. Esto se debe a que la función de devolución…
|
CWE-20
Improper Input Validation
|
CVE-2026-3460
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3487
|
7.2 |
HIGH
Network
|
-
|
-
|
The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3 via the redux_p AJAX action in the bundled ReduxFramework l…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-3478
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3488
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Content Syndication Toolkit para WordPress es vulnerable a falsificación de petición del lado del servidor en todas las versiones hasta la 1.3, inclusive, a través de la acción AJAX redux_p…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-3478
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3489
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.9. This is due to the plugin not properly verifying that a user is auth…
|
CWE-862
Missing Authorization
|
CVE-2026-3506
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3490
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin WP-Chatbot para Messenger para WordPress es vulnerable a una omisión de autorización en todas las versiones hasta la 4.9, inclusive. Esto se debe a que el plugin no verifica correctamente q…
|
CWE-862
Missing Authorization
|
CVE-2026-3506
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3491
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configura…
|
CWE-862
Missing Authorization
|
CVE-2026-3570
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3492
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registe…
|
CWE-202
Exposure of Sensitive Information Through Data Queries
|
CVE-2026-3546
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3493
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin e-shot form builder para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 1.0.2, inclusive. La función eshot_form_builder_get_account_data() e…
|
CWE-202
Exposure of Sensitive Information Through Data Queries
|
CVE-2026-3546
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3494
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Sherk Custom Post Type Displays plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute in all versions up to, and including, 1.2.1. This is due to i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3554
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3495
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Sherk Custom Post Type Displays para WordPress es vulnerable a cross-site scripting almacenado a través del atributo 'title' del shortcode en todas las versiones hasta la 1.2.1, inclusive. …
|
CWE-79
Cross-site Scripting
|
CVE-2026-3554
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3496
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Smarter Analytics para WordPress es vulnerable a acceso no autorizado en todas las versiones hasta la 2.0, inclusive. Esto se debe a la falta de autenticación y comprobaciones de capacidad …
|
CWE-862
Missing Authorization
|
CVE-2026-3570
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3497
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Paypal Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'amount' and 'name' shortcode attributes in all versions up to, and including, 0.3. This is due to insuf…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3617
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3498
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Show Posts list – Easy designs, filters and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_type' shortcode attribute in the 'swiftpost-list' shortcode in all…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4022
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3499
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Show Posts list – Easy designs, filters and more para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de shortcode 'post_type' en el shortcode 'swiftpost-lis…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4022
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3500
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Alfie – Feed Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'naam' parameter in all versions up to, and including, 1.2.1. This is due to missing nonce validation…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4069
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|