Количество 386 939
Количество 386 939
CVE-2026-57759
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
CVE-2026-57758
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
CVE-2026-57757
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
CVE-2026-57756
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
CVE-2026-57755
Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions.
CVE-2026-57754
Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
CVE-2026-57753
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
CVE-2026-57752
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
CVE-2026-57751
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
CVE-2026-57750
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
CVE-2026-5774
Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.
CVE-2026-57749
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
CVE-2026-57748
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
CVE-2026-57747
Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
CVE-2026-57746
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
CVE-2026-57745
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
CVE-2026-57744
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
CVE-2026-57743
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.
CVE-2026-57741
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
CVE-2026-57740
Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57759 Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-57758 Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57757 Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57756 Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions. | CVSS3: 8.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57755 Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57754 Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57753 Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-57752 Contributor SQL Injection in iNET Webkit 1.2.4 versions. | CVSS3: 8.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57751 Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. | CVSS3: 8.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57750 Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
CVE-2026-5774 Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token. | CVSS3: 6.4 | 0% Низкий | 5 месяцев назад | |
CVE-2026-57749 Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57748 Contributor Local File Inclusion in Shopify <= 1.0.0 versions. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57747 Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57746 Subscriber Broken Access Control in Booked <= 3.0.0 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57745 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Reflected XSS.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57744 Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-57743 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5. | CVSS3: 8.1 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-57741 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-57740 Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу