|
4301
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en jgwhite33 WP Review Slider wp-facebook-reviews permite XSS Almacenado. Este pro…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32491
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4302
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-32492
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4303
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación por suplantación en Joe Dolson My Tickets my-tickets permite la suplantación de identidad. Este problema afecta a My Tickets: desde n/a hasta <= 2.1.1.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-32492
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4304
|
- |
-
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32493
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4305
|
- |
-
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en eyecix JobSearch wp-jobsearch permite XSS Reflejado. Este problema afecta a Job…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32493
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4306
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Image Slider by Ays ays-slider allows Exploiting Incorrectly Configured Access Control Se…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32494
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4307
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('Cross-site Scripting') en Ays Pro Image Slider de Ays ays-slider permite la Explotación de Niveles de …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32494
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4308
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Terms Popup: from …
|
CWE-862
Missing Authorization
|
CVE-2026-32495
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4309
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Link Software LLC WP Terms Popup wp-terms-popup permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este probl…
|
CWE-862
Missing Authorization
|
CVE-2026-32495
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4310
|
6.7 |
MEDIUM
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Contact Form 7 wp-contact-form-7-spam-blocker allows Path Traversal.This issue af…
|
CWE-22
Path Traversal
|
CVE-2026-32496
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4311
|
6.7 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') en NYSL Spam Protect para Contact Form 7 wp-contact-form-7-spam-blocker permite el salto de …
|
CWE-22
Path Traversal
|
CVE-2026-32496
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4312
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This issue affects User Verification: from n/a through <= 2.0.45.
|
CWE-1390
Weak Authentication
|
CVE-2026-32497
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4313
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autenticación débil en PickPlugins User Verification user-verification permite el abuso de autenticación. Este problema afecta a User Verification: desde n/a hasta <= 2.0.45.
|
CWE-1390
Weak Authentication
|
CVE-2026-32497
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4314
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-32498
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4315
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Falta de Autorización en Metagauss RegistrationMagic constructor de formularios de registro personalizados con gestor de envíos permite Explotar Niveles de Seguridad de Control de A…
|
CWE-862
Missing Authorization
|
CVE-2026-32498
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4316
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a thro…
|
CWE-89
SQL Injection
|
CVE-2026-32499
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4317
|
9.3 |
CRITICAL
Network
|
-
|
-
|
La vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en el chatbot QuantumCloud ChatBot permite Inyección SQL Ciega. Este problema afe…
|
CWE-89
SQL Injection
|
CVE-2026-32499
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4318
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS MetaMax metamax allows PHP Local File Inclusion.This issue affects …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32500
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4319
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP ('Inclusión Remota de Ficheros PHP') vulnerabilidad en CreativeWS MetaMax metamax permite la Inclusión …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32500
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4320
|
7.1 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Configurat…
|
CWE-862
Missing Authorization
|
CVE-2026-32501
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4321
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en wp-configurator WP Configurator Pro wp-configurator-pro permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este proble…
|
CWE-862
Missing Authorization
|
CVE-2026-32501
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4322
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects Borgholm: from n/a through < 1.6.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32502
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4323
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Select-Themes Borgholm borgholm-marketing-agency-theme permite la inyección de objetos. Este problema afecta a Borgholm: desde n/a hasta &l…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32502
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4324
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Trendustry trendustry allows PHP Local File Inclusion.This issue af…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32503
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4325
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado del nombre de fichero para la declaración include/require en el programa PHP ('inclusión remota de ficheros PHP') en CreativeWS Trendustry trendustry permite la i…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32503
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4326
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS VintWood vintwood allows PHP Local File Inclusion.This issue affect…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32504
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4327
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración Include/Require en el programa PHP (vulnerabilidad de 'Inclusión remota de ficheros PHP') en CreativeWS VintWood vintwood permite la Inclu…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32504
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4328
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CreativeWS Kiddy kiddy allows PHP Local File Inclusion.This issue affects Kidd…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32505
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4329
|
8.1 |
HIGH
Network
|
-
|
-
|
Control inadecuado del nombre de fichero para la declaración include/require en un programa PHP (vulnerabilidad de 'inclusión remota de ficheros PHP') en CreativeWS Kiddy kiddy permite la inclusión l…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32505
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4330
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affects Archicon: from n/a through < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32506
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4331
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Archicon archicon permite la inyección de objetos. Este problema afecta a Archicon: desde n/a hasta < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32506
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4332
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affects Leroux: from n/a through < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32507
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4333
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Elated-Themes Leroux leroux permite la inyección de objetos. Este problema afecta a Leroux: desde n/a hasta < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32507
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4334
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue affects Halstein: from n/a through < 1.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32508
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4335
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Mikado-Themes Halstein halstein permite la inyección de objetos. Este problema afecta a Halstein: desde n/a hasta < 1.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32508
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4336
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects Gracey: from n/a through < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32509
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4337
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Gracey gracey permite la inyección de objetos. Este problema afecta a Gracey: desde n/a hasta < 1.4.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32509
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4338
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affects Kamperen: from n/a through < 1.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32510
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4339
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Kamperen kamperen permite la inyección de objetos. Este problema afecta a Kamperen: desde n/d hasta < 1.3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32510
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4340
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32511
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4341
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Mikado-Themes Stål stal permite la inyección de objetos. Este problema afecta a Stål: desde n/a hasta < 1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32511
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4342
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue affects Pelicula: from n/a through < 1.10.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32512
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4343
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Edge-Themes Pelicula pelicula-video-production-and-movie-theme permite la inyección de objetos. Este problema afecta a Pelicula: desde n/a …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32512
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4344
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection.This issue affects JS Archive List: from n/a through <= 6.1.7.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32513
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4345
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en Miguel Useche JS Archive List jquery-archive-list-widget permite la inyección de objetos. Este problema afecta a JS Archive List: desde n/a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32513
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4346
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Petitioner: from n/a through <= …
|
CWE-862
Missing Authorization
|
CVE-2026-32514
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4347
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por falta de autorización en Anton Voytenko Petitioner petitioner permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta…
|
CWE-862
Missing Authorization
|
CVE-2026-32514
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4348
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Miraculous: from n/a through < 2.1…
|
CWE-862
Missing Authorization
|
CVE-2026-32515
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4349
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en kamleshyadav Miraculous miraculous permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a …
|
CWE-862
Missing Authorization
|
CVE-2026-32515
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4350
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Blind SQL Injection.This issue affects …
|
CWE-89
SQL Injection
|
CVE-2026-32516
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|