Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 382 285

Количество 382 285

nvd логотип

CVE-2026-59529

около 1 месяца назад

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-59528

около 1 месяца назад

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-59527

около 1 месяца назад

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59526

около 1 месяца назад

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59525

около 1 месяца назад

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59524

около 1 месяца назад

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59523

около 2 месяцев назад

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59522

около 1 месяца назад

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59521

около 2 месяцев назад

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-59520

около 2 месяцев назад

Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-59519

около 2 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59518

около 2 месяцев назад

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-59517

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59516

около 2 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59515

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59514

около 1 месяца назад

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-59513

около 1 месяца назад

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59512

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-59511

около 2 месяцев назад

Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59510

около 2 месяцев назад

AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF di

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-59529

Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59528

Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59527

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59526

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59525

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59524

Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59523

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59522

Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59521

Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.

CVSS3: 7.2
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59520

Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.

CVSS3: 4.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59519

Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59518

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59517

Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59516

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59515

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.

CVSS3: 9.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59514

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

CVSS3: 9.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59513

Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.

CVSS3: 6.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59512

Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-59511

Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-59510

AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF di

1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу