Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 959

Количество 389 959

nvd логотип

CVE-2026-57395

2 месяца назад

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57394

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57393

2 месяца назад

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57392

2 месяца назад

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57391

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Stored XSS.This issue affects Loops & Logic: from n/a through <= 4.2.3.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57390

2 месяца назад

Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-5738

16 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-57389

2 месяца назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2026-57388

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57387

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through <= 3.5.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57386

2 месяца назад

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57385

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57384

около 2 месяцев назад

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57383

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57382

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57381

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57380

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-5737

4 месяца назад

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a scheduled favicon fetcher that performs unrestricted cURL requests to stored domains. The signature validation is insufficient because the signature is embedded in publicly-accessible JavaScript and the salt is static per site, allowing attackers to extract valid signatures. The favicon downloader uses raw cURL functions without any SSRF protection mechanisms (no localhost blocking, no private network filtering, and does not use WordPress's wp_safe_remote_* functions). This makes it possible for unauthenticated attackers to inject malicious referrer domains into the database and trigger server-side requests to arbitrary hosts including internal services.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57379

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57378

2 месяца назад

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57395

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57394

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through <= 4.14.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57393

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57392

Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tourfic: from n/a through <= 2.22.5.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57391

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Stored XSS.This issue affects Loops & Logic: from n/a through <= 4.2.3.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57390

Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Extra Product Options Builder for WooCommerce: from n/a through <= 1.2.167.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5738

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.1
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-57389

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traversal.This issue affects Groundhogg: from n/a through <= 4.4.1.

CVSS3: 8.6
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57388

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57387

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue affects picu: from n/a through <= 3.5.1.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57386

Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.

CVSS3: 8.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57385

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57384

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57383

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS.This issue affects JobSearch: from n/a through <= 3.2.9.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57382

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57381

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57380

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-leaflet-map allows DOM-Based XSS.This issue affects Extensions for Leaflet Map: from n/a through <= 5.1.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5737

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a scheduled favicon fetcher that performs unrestricted cURL requests to stored domains. The signature validation is insufficient because the signature is embedded in publicly-accessible JavaScript and the salt is static per site, allowing attackers to extract valid signatures. The favicon downloader uses raw cURL functions without any SSRF protection mechanisms (no localhost blocking, no private network filtering, and does not use WordPress's wp_safe_remote_* functions). This makes it possible for unauthenticated attackers to inject malicious referrer domains into the database and trigger server-side requests to arbitrary hosts including internal services.

CVSS3: 6.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57378

Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Forms: from n/a through <= 1.9.3.7.

CVSS3: 7.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу