Количество 386 296
Количество 386 296
CVE-2026-59560
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
CVE-2026-5955
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.
CVE-2026-59559
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
CVE-2026-59558
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
CVE-2026-59557
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
CVE-2026-59556
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
CVE-2026-59555
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVE-2026-59554
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
CVE-2026-59553
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
CVE-2026-59552
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
CVE-2026-59551
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59550
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
CVE-2026-59549
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59548
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
CVE-2026-59547
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
CVE-2026-59546
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
CVE-2026-59545
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-59544
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVE-2026-59543
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVE-2026-59542
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59560 Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5955 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57. | CVSS3: 9.8 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-59559 Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59558 Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59557 Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59556 Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59555 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | CVSS3: 10 | 1% Низкий | около 1 месяца назад | |
CVE-2026-59554 Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59553 Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59552 Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions. | CVSS3: 7.2 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59551 Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | CVSS3: 8.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59550 Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59549 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59548 Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59547 Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59546 Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions. | CVSS3: 7.4 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59545 Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions. | CVSS3: 8.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59544 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. | CVSS3: 9.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-59543 Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. | CVSS3: 9.9 | 1% Низкий | около 1 месяца назад | |
CVE-2026-59542 Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | CVSS3: 7.7 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу