Количество 386 296
Количество 386 296
CVE-2026-59541
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
CVE-2026-59540
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVE-2026-5953
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
CVE-2026-59539
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
CVE-2026-59538
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
CVE-2026-59537
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
CVE-2026-59536
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59535
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
CVE-2026-59534
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59533
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59532
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
CVE-2026-59531
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
CVE-2026-59530
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVE-2026-5952
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks.
CVE-2026-59529
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-59528
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
CVE-2026-59527
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59526
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59525
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-59524
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59541 Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59540 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5953 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026. | CVSS3: 6.1 | 0% Низкий | 7 дней назад | |
CVE-2026-59539 Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59538 Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59537 Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions. | CVSS3: 7.6 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59536 Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59535 Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59534 Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59533 Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59532 Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59531 Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59530 Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-5952 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protected Maven package metadata due to incorrect authorization checks. | CVSS3: 4.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-59529 Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59528 Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59527 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59526 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59525 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | CVSS3: 9.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-59524 Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу