Количество 374 083
Количество 374 083
CVE-2026-65571
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
CVE-2026-65570
Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
CVE-2026-6556
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed scope can be bypassed by sending a request to the prefixed route, because Fastify still matches the route but the middleware is skipped. Patches: upgrade to @fastify/express 4.0.7. Workarounds: use string mount paths instead of arrays or regular expressions in prefixed plugins, or register one use call per path.
CVE-2026-65569
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
CVE-2026-65568
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
CVE-2026-65567
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
CVE-2026-65565
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
CVE-2026-65564
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
CVE-2026-65563
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
CVE-2026-65562
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
CVE-2026-65561
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
CVE-2026-65560
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-6555
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file.
CVE-2026-65559
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
CVE-2026-65558
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
CVE-2026-65557
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
CVE-2026-65556
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
CVE-2026-65554
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
CVE-2026-65553
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
CVE-2026-65552
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65571 Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | CVSS3: 9.8 | 0% Низкий | 2 дня назад | |
CVE-2026-65570 Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. | CVSS3: 8.1 | 0% Низкий | 2 дня назад | |
CVE-2026-6556 @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths and regular expressions) are left unprefixed inside prefixed plugin scopes, so middleware registered with those forms does not match the actual prefixed request path. Applications that use path-scoped middleware for authentication, authorization, rate limiting, or auditing on routes inside a prefixed scope can be bypassed by sending a request to the prefixed route, because Fastify still matches the route but the middleware is skipped. Patches: upgrade to @fastify/express 4.0.7. Workarounds: use string mount paths instead of arrays or regular expressions in prefixed plugins, or register one use call per path. | CVSS3: 9.1 | 0% Низкий | около 1 месяца назад | |
CVE-2026-65569 Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | CVSS3: 8.5 | 0% Низкий | 2 дня назад | |
CVE-2026-65568 Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions. | CVSS3: 5 | 0% Низкий | 12 дней назад | |
CVE-2026-65567 Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | CVSS3: 5.3 | 0% Низкий | 12 дней назад | |
CVE-2026-65565 Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65564 Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | CVSS3: 5.3 | 0% Низкий | 12 дней назад | |
CVE-2026-65563 Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions. | CVSS3: 5.9 | 0% Низкий | 12 дней назад | |
CVE-2026-65562 Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions. | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-65561 Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions. | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
CVE-2026-65560 Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-6555 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a web-accessible directory. This makes it possible for unauthenticated attackers to upload malicious PHP files and achieve remote code execution by sending a valid first file followed by a malicious file. | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-65559 Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | CVSS3: 7.2 | 0% Низкий | 2 дня назад | |
CVE-2026-65558 Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | CVSS3: 5.4 | 0% Низкий | 12 дней назад | |
CVE-2026-65557 Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | CVSS3: 5.9 | 0% Низкий | 12 дней назад | |
CVE-2026-65556 Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions. | CVSS3: 9.8 | 0% Низкий | 2 дня назад | |
CVE-2026-65554 Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions. | CVSS3: 7.1 | 0% Низкий | 2 дня назад | |
CVE-2026-65553 Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | CVSS3: 10 | 0% Низкий | 2 дня назад | |
CVE-2026-65552 Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | CVSS3: 9.8 | 0% Низкий | 2 дня назад |
Уязвимостей на страницу