Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 959

Количество 389 959

nvd логотип

CVE-2026-57431

3 месяца назад

Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57430

3 месяца назад

Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-5742

5 месяцев назад

The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts that will execute whenever a user accesses a page containing the affected badge widget.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-57429

3 месяца назад

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57428

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57427

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57426

2 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57425

около 2 месяцев назад

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57424

2 месяца назад

Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57423

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57422

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57421

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57420

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5741

5 месяцев назад

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-57419

2 месяца назад

Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 3.1.8.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57418

2 месяца назад

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57417

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Cart Lift cart-lift allows Stored XSS.This issue affects Cart Lift: from n/a through <= 3.1.57.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57416

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57415

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57414

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57431

Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57430

Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5742

The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and improper output escaping when rendering user profile data in badge widgets. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts that will execute whenever a user accesses a page containing the affected badge widget.

CVSS3: 6.4
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57429

Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57428

Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57427

Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57426

Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57425

Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57424

Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57423

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Message Filter for Contact Form 7 cf7-message-filter allows Reflected XSS.This issue affects Message Filter for Contact Form 7: from n/a through <= 1.6.3.8.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57422

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Bopo – WooCommerce Product Bundle Builder bopo-woo-product-bundle-builder allows Reflected XSS.This issue affects Bopo – WooCommerce Product Bundle Builder: from n/a through <= 1.2.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57421

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57420

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netrr Author Box WP Lens author-box-for-divi allows Stored XSS.This issue affects Author Box WP Lens: from n/a through <= 2.1.5.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5741

A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_container/remove_container/pull_image of the file src/index.ts of the component HTTP Interface. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-57419

Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 3.1.8.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57418

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57417

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RexTheme Cart Lift cart-lift allows Stored XSS.This issue affects Cart Lift: from n/a through <= 3.1.57.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57416

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57415

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codemenschen Gift Vouchers gift-voucher allows Stored XSS.This issue affects Gift Vouchers: from n/a through <= 4.7.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57414

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу