Vulnerabilities in Unknown

5,582 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-19222MEDIUMForminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role BypassEPSS 0.4%CVE-2022-2375—WP Sticky Button < 1.4.1 - Unauthenticated Arbitrary Settings Update to Stored XSSEPSS 0.4%CVE-2022-2382—Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options DeletionEPSS 0.4%CVE-2022-2389—Automations By Autonami < 2.1.2 - Subscriber+ Automation CreationEPSS 0.4%CVE-2024-5199MEDIUMSpotify Play Button <= 1.0 - Contributor+ Stored XSSEPSS 0.4%CVE-2022-2377—Directorist < 7.3.0 - Subscriber+ Arbitrary E-mail SendingEPSS 0.4%CVE-2024-4970MEDIUMWidget Bundle <= 2.0.0 - Admin+ Stored XSSEPSS 0.4%CVE-2022-1956—Shortcut Macros <= 1.3 - Subscriber+ Arbitrary Settings UpdateEPSS 0.4%CVE-2024-10104MEDIUMJobs for WordPress < 2.7.8 - Contributor+ Stored XSSEPSS 0.4%CVE-2024-11356MEDIUMTourmaster < 5.3.4 - Unauthenticated Stored XSS via Room BookingEPSS 0.4%CVE-2024-4384MEDIUMCSSable Countdown <= 1.5 - Admin+ Stored XSSEPSS 0.4%CVE-2023-4826MEDIUMSocialdriver < 2024 - Prototype Pollution to XSSEPSS 0.4%CVE-2024-11644MEDIUMWP-SVG <= 0.9 - Contributor+ Stored XSS via ShortcodeEPSS 0.4%CVE-2026-14920HIGHAcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] ParameterEPSS 0.4%CVE-2024-3899MEDIUMEnvira Gallery < 1.8.15 - Author+ Stored XSSEPSS 0.4%CVE-2024-6710MEDIUMDitty < 3.1.45 - Author+ Stored XSSEPSS 0.4%CVE-2025-3471MEDIUMSureForms < 1.4.4 - Contributor+ Settings UpdateEPSS 0.4%CVE-2024-6270MEDIUMCommunity Events < 1.5.1 - Admin+ Stored XSSEPSS 0.4%CVE-2024-7918MEDIUMPocket Widget <= 0.1.3 - Admin+ Stored XSSEPSS 0.4%CVE-2024-6910MEDIUMEventON < 2.2.17 - Admin+ Stored XSSEPSS 0.4%