Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 083

Количество 374 083

nvd логотип

CVE-2026-65532

16 дней назад

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-65531

16 дней назад

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-65530

16 дней назад

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-6552

около 2 месяцев назад

Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.

EPSS: Низкий
nvd логотип

CVE-2026-65529

16 дней назад

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65528

16 дней назад

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65527

16 дней назад

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65526

16 дней назад

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-65525

16 дней назад

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65524

16 дней назад

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-65523

2 дня назад

Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-65522

16 дней назад

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65521

16 дней назад

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-65520

2 дня назад

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2026-6551

3 месяца назад

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
EPSS: Низкий
nvd логотип

CVE-2026-65519

16 дней назад

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65518

16 дней назад

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-65517

2 дня назад

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-65516

16 дней назад

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2026-65515

2 дня назад

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65532

Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.

CVSS3: 7.6
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65531

Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.

CVSS3: 4.8
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65530

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-6552

Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.

около 2 месяцев назад
nvd логотип
CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65528

Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65527

Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65526

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer allows Blind SQL Injection. This issue affects Visualizer: from n/a through 4.0.1.

CVSS3: 8.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65524

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

CVSS3: 4.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65523

Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.

CVSS3: 7.5
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65522

Contributor Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65521

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

CVSS3: 5.3
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

CVSS3: 9.3
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-6551

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions up to, and including, 1.1.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 6.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-65519

Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65518

Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.

CVSS3: 6.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65517

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

CVSS3: 7.1
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-65516

Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.

CVSS3: 7.2
0%
Низкий
16 дней назад
nvd логотип
CVE-2026-65515

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.

CVSS3: 7.1
0%
Низкий
2 дня назад

Уязвимостей на страницу