Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 393 454

Количество 393 454

nvd логотип

CVE-2026-57713

2 месяца назад

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-57712

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57711

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57710

2 месяца назад

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.

CVSS3: 9.9
EPSS: Низкий
nvd логотип

CVE-2026-57709

2 месяца назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2026-57708

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57707

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-57706

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57705

2 месяца назад

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57704

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57703

около 2 месяцев назад

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-57702

2 месяца назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-57701

около 2 месяцев назад

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57700

3 месяца назад

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2026-57699

около 2 месяцев назад

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57698

2 месяца назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57697

2 месяца назад

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-57696

около 2 месяцев назад

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57695

2 месяца назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-57694

2 месяца назад

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-57713

Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6.

CVSS3: 8.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57712

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57711

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57710

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through <= 14.1.7.

CVSS3: 9.9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57709

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Path Traversal.This issue affects Membership For WooCommerce: from n/a through <= 3.1.0.

CVSS3: 8.6
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57708

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Contact Form Entries contact-form-entries allows Reflected XSS.This issue affects Contact Form Entries: from n/a through <= 1.5.2.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57707

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4.

CVSS3: 9.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57706

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57705

Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57704

Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57703

Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions.

CVSS3: 6.3
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57702

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.

CVSS3: 9.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57701

Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

CVSS3: 10
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57699

Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57698

Authentication Bypass Using an Alternate Path or Channel vulnerability in VillaTheme Abandoned Cart Recovery for WooCommerce woo-abandoned-cart-recovery allows Authentication Abuse.This issue affects Abandoned Cart Recovery for WooCommerce: from n/a through <= 1.1.12.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57697

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57696

Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.

CVSS3: 7.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-57695

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Rossiter Document Gallery document-gallery allows Reflected XSS.This issue affects Document Gallery: from n/a through <= 5.1.0.

CVSS3: 7.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57694

Authorization Bypass Through User-Controlled Key vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tutor LMS: from n/a through <= 3.9.13.

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу