|
3501
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Paypal Shortcode para WordPress es vulnerable a cross-site scripting almacenado a través de los atributos de shortcode 'amount' y 'name' en todas las versiones hasta la 0.3, inclusive. Esto…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3617
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3502
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Sheets2Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titles' shortcode attribute in the [sheets2table-render-table] shortcode in all versions up to and includin…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3619
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3503
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Sheets2Table para WordPress es vulnerable a cross-site scripting almacenado a través del atributo de shortcode 'titles' en el shortcode [sheets2table-render-table] en todas las versiones ha…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3619
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3504
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. This is due to the plugin registering a public REST API webhook endpoint at /we…
|
CWE-20
Improper Input Validation
|
CVE-2026-3641
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3505
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Appmax para WordPress es vulnerable a la Validación de Entrada Inadecuada en todas las versiones hasta la 1.0.3, inclusive. Esto se debe a que el plugin registra un endpoint de webhook de A…
|
CWE-20
Improper Input Validation
|
CVE-2026-3641
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3506
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ecover Builder For Dummies plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'ecover' shortcode in all versions up to and including 1.0. This is due …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4077
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3507
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ecover Builder For Dummies para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'id' del shortcode 'ecover' en todas las versiones hasta la 1.0 inclusive. E…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4077
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3508
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Pre* Party Resource Hints plugin for WordPress is vulnerable to SQL Injection via the 'hint_ids' parameter of the pprh_update_hints AJAX action in all versions up to, and including, 1.8.20. This …
|
CWE-89
SQL Injection
|
CVE-2026-4087
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3509
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.1. The save_config() function, which handles the 'punnel_save_c…
|
CWE-862
Missing Authorization
|
CVE-2026-3645
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3510
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Punnel – Landing Page Builder para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 1.3.1, inclusive. La función save_config(), que maneja la acción AJAX '…
|
CWE-862
Missing Authorization
|
CVE-2026-3645
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3511
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.23. This is due to the plugin registering the 'build-app-online-update-vendor-…
|
CWE-862
Missing Authorization
|
CVE-2026-3651
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3512
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Build App Online para WordPress es vulnerable a acceso no autorizado en todas las versiones hasta la 1.0.23, inclusive. Esto se debe a que el plugin registra la acción AJAX 'build-app-onlin…
|
CWE-862
Missing Authorization
|
CVE-2026-3651
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3513
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1beta. This is due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3996
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3514
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Pre* Party Resource Hints para WordPress es vulnerable a inyección SQL a través del parámetro 'hint_ids' de la acción AJAX pprh_update_hints en todas las versiones hasta e incluyendo la 1.8…
|
CWE-89
SQL Injection
|
CVE-2026-4087
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3515
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Neos Connector for Fakturama plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.0.14. This is due to missing nonce validation in the ncff_add_p…
|
CWE-352
Origin Validation Error
|
CVE-2026-4143
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3516
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Neos Connector for Fakturama para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 0.0.14 inclusive. Esto se debe a la falta de vali…
|
CWE-352
Origin Validation Error
|
CVE-2026-4143
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3517
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Review Map by RevuKangaroo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.7 due to insufficient input sanitizati…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3518
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Games Embed para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode [game] en todas las versiones hasta la 0.1beta inclusive. Esto se debe a una sanitizació…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3996
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3519
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Text Toggle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' shortcode attribute of the [tt_part] and [tt] shortcodes in all versions up to and including 1.1. Thi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3997
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3520
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Text Toggle para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del atributo 'title' del shortcode de los shortcodes [tt_part] y [tt] en todas las versiones hasta la 1.1…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3997
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3521
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all versions up to, and including, 3.0.2. This is due to missing capability checks…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3522
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Task Manager para WordPress es vulnerable a la ejecución arbitraria de shortcodes a través de la acción AJAX 'search' en todas las versiones hasta la 3.0.2, inclusive. Esto se debe a la fal…
|
CWE-94
Code Injection
|
CVE-2026-4004
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3523
|
4.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Review Map by RevuKangaroo para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración del plugin en todas las versiones hasta la 1.7, inclusive, debido a un…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4161
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3524
|
8.8 |
HIGH
Network
|
-
|
-
|
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2. This is due to the plugin allowing a user to update the 'on_expire_default_to_…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3525
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Expire Users para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta la 1.2.2, inclusive. Esto se debe a que el plugin permite a un usuario actualizar el meta 'o…
|
CWE-862
Missing Authorization
|
CVE-2026-4261
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3526
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black …
|
CWE-183 CWE-184
Permissive List of Allowed Inputs Incomplete Blacklist
|
CVE-2026-4509
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3527
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ad Short plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ad' shortcode's 'client' attribute in all versions up to and including 2.0.1. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4067
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3528
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Ad Short para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del atributo 'client' del shortcode 'ad' en todas las versiones hasta la 2.0.1 inclusive. Esto se debe a una…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4067
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3529
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin Alfie – Feed Plugin para WordPress es vulnerable a Stored Cross-Site Scripting a través del parámetro 'naam' en todas las versiones hasta la 1.2.1, inclusive. Esto se debe a la falta de val…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4069
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3530
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WordPress PayPal Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donate' shortcode in all versions up to, and including, 1.01. This is due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4072
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3531
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WordPress PayPal Donation para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'donate' en todas las versiones hasta la 1.01, inclusive. Esto se debe a una …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4072
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3532
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The fyyd podcast shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fyyd-podcast', 'fyyd-episode', and 'fyyd' shortcodes in all versions up to, and including, 0.3.1…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4084
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3533
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en PbootCMS hasta la versión 3.2.12. Esto afecta una función desconocida del archivo core/function/file.php del componente Carga de Archivos. La manipulació…
|
CWE-183 CWE-184
Permissive List of Allowed Inputs Incomplete Blacklist
|
CVE-2026-4509
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3534
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipu…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4510
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3535
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en PbootCMS hasta 3.2.12. Esto afecta a la función alert_location del archivo apps/home/controller/MemberController.php del componente Gestor de Parámetros. Esta mani…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4510
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3536
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin de shortcodes fyyd podcast para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los shortcodes 'fyyd-podcast', 'fyyd-episode' y 'fyyd' en todas las versiones hasta la …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4084
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3537
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the 'wp_random_button' shortcode in all versions up t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4086
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3538
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Random Button para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los atributos del shortcode 'cat', 'nocat' y 'text' del shortcode 'wp_random_button' en todas las…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4086
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3539
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.5.9. The `speedup01_ajax_enabled()` function, which handles the `wp_ajax_spe…
|
CWE-862
Missing Authorization
|
CVE-2026-4127
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3540
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Speedup Optimization para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 1.5.9 inclusive. La función speedup01_ajax_enabled(), que maneja la acción AJAX …
|
CWE-862
Missing Authorization
|
CVE-2026-4127
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3541
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-4511
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3542
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en vanna-ai vanna hasta la versión 2.0.2. Afectada es la función exec del archivo /src/vanna/legacy. Dicha manipulación conduce a inyección. El ataqu…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-4511
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3543
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injectio…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4513
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3544
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en vanna-ai vanna hasta 2.0.2. Afectada por esta vulnerabilidad es la función ask del archivo vanna\legacy\base\base.py. Realizar una manipulación resulta en inyecció…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4513
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3545
|
7.5 |
HIGH
Network
|
-
|
-
|
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' metho…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-4373
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3546
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin JetFormBuilder para WordPress es vulnerable a la lectura arbitraria de archivos a través de salto de ruta en todas las versiones hasta la 3.5.6.2, inclusive. Esto se debe a que el método 'U…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-4373
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3547
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a …
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-4514
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3548
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en PbootCMS hasta la versión 3.2.12. Se ve afectada por este problema alguna funcionalidad desconocida del archivo apps/admin/controller/system/UserController.PHP …
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-4514
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3549
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sched: ets: fix divide by zero in the offload path
Offloading ETS requires computing each class' WRR weight: this is done by
…
|
CWE-369
Divide By Zero
|
CVE-2026-23379
|
2026-04-25 01:24 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3550
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
net/sched: ets: corregir división por cero en la ruta de descarga
La descarga de ETS requiere calcular el peso WRR de cada clase…
|
CWE-369
Divide By Zero
|
CVE-2026-23379
|
2026-04-25 01:24 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|