Vulnerabilities in Softaculous
39 resultsVexday analysis
Softaculous apresenta um perfil de risco moderado com 10 vulnerabilidades catalogadas, sendo apenas 1 crítica (CVSS alto) e nenhuma sob exploração ativa conhecida. A fraqueza dominante é a falsificação de solicitação entre sites (CWE-352), padrão em aplicações web, com publicação recente de 1 vulnerabilidade nos últimos 90 dias que demanda monitoramento contínuo.
CVE-2024-2127MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom AttributesEPSS 0.3%CVE-2026-5114MEDIUMSpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File ReadEPSS 0.3%CVE-2024-13430MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcodeEPSS 0.3%CVE-2024-2324MEDIUMFileOrganizer and FileOrganizer Pro <= 1.0.6 - Authenticated Stored Cross-Site ScriptingEPSS 0.3%CVE-2026-2442MEDIUMPagelayer <= 2.0.7 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email'EPSS 0.3%CVE-2026-2470MEDIUMPagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'EPSS 0.3%CVE-2022-45079MEDIUMWordPress Loginizer Plugin <= 1.7.5 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2025-2104MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post PublicationEPSS 0.3%CVE-2024-13427MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button LinkEPSS 0.3%CVE-2025-12814MEDIUMSiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings ResetEPSS 0.3%CVE-2025-13085MEDIUMSiteSEO – SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta DisclosureEPSS 0.2%CVE-2025-12366MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object ReferenceEPSS 0.2%CVE-2026-3297MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor BlockEPSS 0.2%CVE-2025-12367MEDIUMSiteSEO – SEO Simplified <= 1.3.1 - Missing Authorization to Authenticated (Author+) Plugin Settings UpdateEPSS 0.2%CVE-2026-59519MEDIUMWordPress FormLayer plugin <= 1.0.6 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-9277MEDIUMSiteSEO – SEO Simplified <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Broken Regex ExpressionEPSS 0.2%CVE-2024-43299MEDIUMWordPress SpeedyCache plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2026-39469MEDIUMWordPress PageLayer plugin <= 2.0.8 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2025-1926MEDIUMPage Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents ModificationEPSS 0.2%