Количество 386 296
Количество 386 296
CVE-2026-5736
A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-57369
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.
CVE-2026-57368
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.
CVE-2026-57367
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
CVE-2026-57366
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.
CVE-2026-57365
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 & v3) for Asgaros Forum: from n/a through <= 1.1.0.
CVE-2026-57364
Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More: from n/a through <= 2.2.0.
CVE-2026-57363
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
CVE-2026-57362
Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
CVE-2026-57361
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
CVE-2026-57360
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
CVE-2026-5735
Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
CVE-2026-57359
Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.
CVE-2026-57358
Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.
CVE-2026-57357
Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.
CVE-2026-57356
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
CVE-2026-57355
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
CVE-2026-57354
Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
CVE-2026-57353
Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.
CVE-2026-57352
Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-5736 A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component detailPlus Endpoint. The manipulation of the argument customQuery leads to sql injection. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet. | CVSS3: 7.3 | 0% Низкий | 5 месяцев назад | |
CVE-2026-57369 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57368 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57367 Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57366 Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57365 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 & v3) for Asgaros Forum: from n/a through <= 1.1.0. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57364 Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More: from n/a through <= 2.2.0. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57363 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57362 Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57361 Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57360 Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-5735 Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. | CVSS3: 9.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-57359 Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57358 Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57357 Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57356 Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57355 Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57354 Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57353 Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57352 Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions. | CVSS3: 4.8 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу