Количество 384 604
Количество 384 604
CVE-2026-59536
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59535
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
CVE-2026-59534
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59533
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59532
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
CVE-2026-59531
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
CVE-2026-59530
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVE-2026-5952
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks.
CVE-2026-59529
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-59528
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
CVE-2026-59527
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59526
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59525
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-59524
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
CVE-2026-59523
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
CVE-2026-59522
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
CVE-2026-59521
Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15.
CVE-2026-59520
Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16.
CVE-2026-59519
Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6.
CVE-2026-59518
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59536 Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59535 Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59534 Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59533 Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59532 Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59531 Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59530 Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5952 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-59529 Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59528 Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59527 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59526 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59525 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59524 Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59523 Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59522 Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59521 Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | CVSS3: 7.2 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-59520 Cross-Site Request Forgery (CSRF) vulnerability in properfraction CrawlWP SEO allows Cross Site Request Forgery. This issue affects CrawlWP SEO: from n/a through 3.0.16. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59519 Insertion of Sensitive Information Into Sent Data vulnerability in Softaculous FormLayer allows Retrieve Embedded Sensitive Data. This issue affects FormLayer: from n/a through 1.0.6. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59518 Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад |
Уязвимостей на страницу