Vulnerabilities in Unknown

5,582 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2022-0634—ThirstyAffiliates < 3.10.5 - Subscriber+ unauthorized image upload + CSRFEPSS 0.3%CVE-2025-14072MEDIUMNinja Forms < 3.13.3 - Unauthenticated Token Generation and Submission DisclosureEPSS 0.3%CVE-2024-7692MEDIUMFlaming Forms <= 1.0.1 - Reflected XSSEPSS 0.3%CVE-2026-16734HIGHStripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount ManipulationEPSS 0.3%CVE-2024-10545LOWNextGEN Gallery < 3.59.9 - Admin+ Stored XSSEPSS 0.3%CVE-2026-15958CRITICALEasy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAXEPSS 0.3%CVE-2026-77012CRITICALIcollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing PasswordEPSS 0.3%CVE-2023-6946HIGHAutotitle for WordPress <= 1.0.3 - Settings Update to Stored XSS via CSRFEPSS 0.3%CVE-2026-80340MEDIUMPayment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PII Disclosure via order-payEPSS 0.3%CVE-2024-6272MEDIUMSpiderContacts <= 1.1.7 - Reflected XSSEPSS 0.3%CVE-2026-13402MEDIUMRoyal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template DisclosureEPSS 0.3%CVE-2026-77758MEDIUMStripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed SessionEPSS 0.3%CVE-2026-81021MEDIUMSupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment DisclosureEPSS 0.3%CVE-2026-88995MEDIUMBookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability CheckEPSS 0.3%CVE-2026-87896MEDIUMRox Appointment Booking < 1.2.8 - Unauthenticated Staff PII Disclosure via Agent REST RouteEPSS 0.3%CVE-2026-87907MEDIUMRox Appointment Booking < 1.2.8 - Unauthenticated Internal Notes Disclosure via Service and Category REST RoutesEPSS 0.3%CVE-2026-77773MEDIUMSocial Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entryEPSS 0.3%CVE-2024-5767HIGHSitetweet <= 0.2 - Stored XSS via CSRFEPSS 0.3%CVE-2026-86796MEDIUMWP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request ParametersEPSS 0.3%CVE-2026-81022MEDIUMSupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code LeakEPSS 0.3%