Vulnerabilities in Unknown

5,554 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-14333HIGHDemi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup DirectoryEPSS 0.4%CVE-2026-12687HIGHProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group IDEPSS 0.4%CVE-2026-16561HIGHSunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment DisclosureEPSS 0.4%CVE-2026-13152HIGHCustom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-13610HIGHKiviCare < 4.5.2 - Unauthenticated Privilege Escalation via RegistrationEPSS 0.4%CVE-2024-1589MEDIUMSendPress Newsletters <= 1.23.11.6 - Admin+ Stored XSS via Form SettingsEPSS 0.4%CVE-2023-4858MEDIUMWP Simple Table Manager Plugin <= 1.5.6 - Admin+ Stored Cross-Site ScriptingEPSS 0.4%CVE-2023-6843MEDIUMeasy.jobs < 2.4.7 - Subscriber+ Arbitrary Settings UpdateEPSS 0.4%CVE-2023-6165MEDIUMRestrict Usernames Emails Characters Plugin < 3.1.4 - Admin+ Stored XSSEPSS 0.4%CVE-2023-5352MEDIUMAwesome Support < 6.1.5 - Insufficient permission check in wpas_edit_replyEPSS 0.4%CVE-2023-6384MEDIUMWP User Profile Avatar < 1.0.1 - Author+ Avatar Deletion/Update via IDOREPSS 0.4%CVE-2024-6223MEDIUMSend email only on Reply to My Comment <= 1.0.6 - Reflected XSSEPSS 0.4%CVE-2024-2118MEDIUMSocial Media Share Buttons < 2.8.9 - Admin+ Stored XSS via settingsEPSS 0.4%CVE-2026-13693MEDIUMBit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path TraversalEPSS 0.4%CVE-2026-16538CRITICALTeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-UpEPSS 0.4%CVE-2022-2276—WP Edit Menu < 1.5.0 - Unauthenticated Arbitrary Post DeletionEPSS 0.4%CVE-2026-16534CRITICALImport and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV ImportEPSS 0.4%CVE-2022-3899HIGH3DPrint < 3.5.6.9 - Arbitrary File and Directory Deletion via CSRFEPSS 0.4%CVE-2025-15609HIGHFortis For WooCommerce < 1.3.1 - Sensitive API Key DisclosureEPSS 0.4%CVE-2023-4783MEDIUMMagee Shortcodes <= 2.1.1 - Contributor+ Stored XSS via shortcodeEPSS 0.4%