|
4651
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/explorer/userShare.class.php of the component Public Share Handler. Such manipu…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4830
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4652
|
5.6 |
MEDIUM
Network
|
-
|
-
|
Se identificó una vulnerabilidad en kalcaddle kodbox 1.64. Este problema afecta a la función Add del archivo app/controller/explorer/userShare.class.php del componente Gestor de Compartición Pública.…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4830
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4653
|
3.7 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protecte…
|
CWE-287
Improper Authentication
|
CVE-2026-4831
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4654
|
3.7 |
LOW
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en kalcaddle kodbox 1.64. Afectada es la función can del archivo /workspace/source-code/app/controller/explorer/auth.class.php del componente Gestor de Comp…
|
CWE-287
Improper Authentication
|
CVE-2026-4831
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4655
|
3.3 |
LOW
Local
|
-
|
-
|
Se ha identificado una debilidad en Orc discount hasta 3.0.1.2. Este problema afecta a la función compile del archivo markdown.c del componente Markdown Gestor. Esta manipulación causa recursión inco…
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-4833
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4656
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Accounting System 1.0. El elemento afectado es una función desconocida del archivo /my_account/delete.php. Realizar una manipulación del argumento co…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4836
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4657
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1986
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4658
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin FloristPress para Woo – Personaliza tu tienda de comercio electrónico para tu floristería para WordPress es vulnerable a cross-site scripting reflejado a través del parámetro 'noresults' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1986
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4659
|
7.2 |
HIGH
Network
|
-
|
-
|
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-3328
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4660
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Frontend Admin de DynamiApps para WordPress es vulnerable a Inyección de Objetos PHP a través de la deserialización del 'post_content' de publicaciones de tipo admin_form en todas las versi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-3328
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4661
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4075
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4662
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin BWL Advanced FAQ Manager Lite para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'baf_sbox' en todas las versiones hasta la 1.1.1 inclusive. Esto se debe …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4075
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4663
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4335
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4664
|
5.4 |
MEDIUM
Network
|
-
|
-
|
El plugin ShortPixel Image Optimizer para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del post_title del adjunto en todas las versiones hasta la 6.4.3, inclusive. Esto se debe …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4335
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4665
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql inj…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4666
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una falla en SourceCodester Malawi Online Market 1.0. El elemento afectado es una función desconocida del archivo /display.PHP. La ejecución de una manipulación del argumento ID pued…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4667
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argum…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4668
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en SourceCodester Food Ordering System 1.0. Esto afecta una función desconocida del archivo /purchase.PHP del componente Gestor de Parámetros. La manipulación de…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4669
|
8.8 |
HIGH
Network
|
-
|
-
|
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objec…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4670
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Amelia Booking para WordPress es vulnerable a Referencias Directas Inseguras a Objetos en versiones hasta la 9.1.2, inclusive. Esto se debe a que el plugin proporciona acceso controlado por…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4671
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4672
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Simple Download Counter para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del shortcode 'sdc_menu' en todas las versiones hasta la 2.3, inclusive. Esto se debe a una s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4673
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the conne…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4674
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all vers…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4675
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El fragmento DSGVO para Leaflet Map y su plugin Extensions para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los shortcodes 'leafext-cookie-time' y 'leafext-delete-cookie' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4676
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin FormLift for Infusionsoft Web Forms para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 7.5.21, inclusive. Esto se debe a la falta de comprobaciones de c…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4677
|
7.2 |
HIGH
Network
|
-
|
-
|
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4678
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Blackhole for Bad Bots para WordPress es vulnerable a cross-site scripting almacenado a través del encabezado HTTP User-Agent en todas las versiones hasta la 3.8 inclusive. Esto se debe a u…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4679
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4680
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Blog2Social: Social Media Auto Post & Scheduler para WordPress es vulnerable a la pérdida de datos no autorizada en todas las versiones hasta la 8.8.2, inclusive. Esto se debe a que la …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4681
|
8.8 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Perf…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4682
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4683
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en el sistema de pedidos de comida en línea code-projects 1.0. Esto afecta una parte desconocida del archivo form/cart.PHP del componente Módulo de Carrito de Compras…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4684
|
8.8 |
HIGH
Network
|
-
|
-
|
Se ha descubierto una vulnerabilidad de seguridad en Netcore Power 15AX hasta la versión 3.0.0.6938. Afectada por este problema es la función setTools del archivo /bin/netis.cgi del componente Diagno…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4685
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Para…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4686
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en itsourcecode Online Enrollment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /sms/grades/index.php?view=edit&id=1 del …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4687
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin.php of the component Admin Login Module. The manipulation …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4844
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4688
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Online Food Ordering System 1.0. Este problema afecta algún procesamiento desconocido del archivo /admin.php del componente Módulo de Inicio de Sesió…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4844
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4689
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exposure in all versions up to, and including, 3.35.7. This is due to a logic erro…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1206
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4690
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Elementor Website Builder para WordPress es vulnerable a una Autorización Incorrecta que conduce a la Exposición de Información Sensible en todas las versiones hasta la 3.35.7, inclusive. E…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1206
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4691
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/index.html. This manipulation of the argument Search causes cross site scripting. I…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4845
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4692
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado un fallo en dameng100 muucmf 1.9.5.20260309. Afecta a una función desconocida del archivo /admin/Member/index.html. Esta manipulación del argumento Search causa cross-site scripting.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4845
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4693
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the file channel/admin.Account/autoReply.html. Such manipulation of the argument keyw…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4846
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4694
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en dameng100 muucmf 1.9.5.20260309. El elemento afectado es una función desconocida del archivo channel/admin.Account/autoReply.html. Dicha manipulación del argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4846
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4695
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results i…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4847
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4696
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se encontró una vulnerabilidad en dameng100 muucmf 1.9.5.20260309. El elemento afectado es una función desconocida del archivo /admin/config/list.html. La manipulación del argumento Name resulta en c…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4847
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4697
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/extend/list.html. Executing a manipulation of the argument Name can lead to cros…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4848
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4698
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue determinada en dameng100 muucmf 1.9.5.20260309. Esto afecta una función desconocida del archivo /admin/extend/list.html. Ejecutar una manipulación del argumento Name puede llev…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4848
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4699
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonRedisSerializer of the file src/main/java/com/genersoft/iot/vmp/conf/redis/Redis…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2026-4860
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4700
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file /goform/formConfigDnsFilterGlobal of the component Paramet…
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-4862
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|