Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 386 939

Количество 386 939

nvd логотип

CVE-2026-57779

около 2 месяцев назад

Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57778

около 2 месяцев назад

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57777

3 дня назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-57776

около 2 месяцев назад

Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57774

около 2 месяцев назад

Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57773

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-57772

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57771

около 2 месяцев назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57770

около 2 месяцев назад

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-5776

4 месяца назад

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-57769

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57768

около 2 месяцев назад

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-57767

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57766

2 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57765

2 месяца назад

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57764

2 месяца назад

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57763

2 месяца назад

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57762

2 месяца назад

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-57761

2 месяца назад

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57760

2 месяца назад

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57779

Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57778

Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57777

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0.

CVSS3: 7.6
0%
Низкий
3 дня назад
nvd логотип
CVE-2026-57776

Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57774

Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57773

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zorem Advanced Shipment Tracking for WooCommerce woo-advanced-shipment-tracking allows Blind SQL Injection.This issue affects Advanced Shipment Tracking for WooCommerce: from n/a through <= 4.0.

CVSS3: 7.6
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0.

CVSS3: 8.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.

CVSS3: 8.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57770

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-5776

The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks

CVSS3: 6.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57769

Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57768

Incorrect Privilege Assignment vulnerability in favethemes Houzez Login Register houzez-login-register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through <= 3.3.3.

CVSS3: 8.2
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57767

Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57766

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

CVSS3: 8.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57764

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57763

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57762

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

CVSS3: 5.9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57761

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57760

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

CVSS3: 5.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу