Количество 382 285
Количество 382 285
CVE-2026-59529
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-59528
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
CVE-2026-59527
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59526
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59525
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-59524
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
CVE-2026-59523
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
CVE-2026-59522
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-59521
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
CVE-2026-59520
Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.
CVE-2026-59519
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.
CVE-2026-59518
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
CVE-2026-59517
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
CVE-2026-59516
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.
CVE-2026-59515
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4.
CVE-2026-59514
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-59513
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
CVE-2026-59512
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
CVE-2026-59511
Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9.
CVE-2026-59510
AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF di
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59529 Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59528 Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59527 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59526 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59525 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59524 Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59523 Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59522 Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59521 Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | CVSS3: 7.2 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-59520 Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59519 Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59518 Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-59517 Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59516 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59515 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4. | CVSS3: 9.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59514 Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59513 Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59512 Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59511 Insertion of Sensitive Information Into Sent Data vulnerability in Tim Strifler Exclusive Addons Elementor allows Retrieve Embedded Sensitive Data. This issue affects Exclusive Addons Elementor: from n/a through 2.7.9.9. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59510 AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that the resolved path remained within the intended PDF_FOLDER directory. An authenticated attacker able to invoke PDF object operations with a crafted identifier could use relative traversal sequences or absolute path components to cause AIL Framework to open files located outside the PDF storage directory. This could allow disclosure of files readable by the AIL process, including application configuration, credentials, or other sensitive local data. This vulnerability is potential due to additional errors before being able to be executed. The fix canonicalises the resulting path with os.path.realpath() and rejects paths whose common directory is outside the configured PDF di | 1% Низкий | около 2 месяцев назад |
Уязвимостей на страницу