Количество 390 981
Количество 390 981
CVE-2026-56041
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
CVE-2026-56040
Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions.
CVE-2026-5603
A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue.
CVE-2026-56039
Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions.
CVE-2026-56038
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
CVE-2026-56037
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3.
CVE-2026-56036
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
CVE-2026-56035
Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions.
CVE-2026-56034
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
CVE-2026-56033
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
CVE-2026-56032
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
CVE-2026-56031
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
CVE-2026-56030
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
CVE-2026-5602
A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVE-2026-56029
Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.
CVE-2026-56028
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
CVE-2026-56027
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
CVE-2026-56026
Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.
CVE-2026-56025
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
CVE-2026-56024
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56041 Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56040 Unauthenticated Cross Site Scripting (XSS) in Gutenverse Form <= 2.4.7 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-5603 A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the patch is aa1ffcc0aea1b212c69787391783af27df15ae9d. A patch should be applied to remediate this issue. | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-56039 Unauthenticated Cross Site Scripting (XSS) in Quick Interest Slider <= 3.1.6 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56038 Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-56037 Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-56036 Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. | CVSS3: 9.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-56035 Unauthenticated Multiple Vulnerabilities in BitFire Security <= 5.0.3 versions. | CVSS3: 8.6 | 0% Низкий | 3 месяца назад | |
CVE-2026-56034 Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. | CVSS3: 9.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-56033 Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-56032 Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-56031 Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-56030 Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-5602 A vulnerability was determined in Nor2-io heim-mcp up to 0.1.3. Impacted is the function registerTools of the file src/tools.ts of the component new_heim_application/deploy_heim_application/deploy_heim_application_to_cloud. This manipulation causes os command injection. The attack requires local access. The exploit has been publicly disclosed and may be utilized. Patch name: c321d8af25f77668781e6ccb43a1336f9185df37. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
CVE-2026-56029 Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-56028 Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-56027 Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | CVSS3: 9.9 | 0% Низкий | 3 месяца назад | |
CVE-2026-56026 Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions. | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-56025 Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-56024 Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу