Vulnerabilities in Unknown

5,582 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-78125MEDIUMLearnPress – Sepay Payment < 4.0.3 - Unauthenticated Order Status DisclosureEPSS 0.3%CVE-2026-77754MEDIUMKirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apisEPSS 0.3%CVE-2026-14240MEDIUMTourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order ExportEPSS 0.3%CVE-2026-80339MEDIUMPayment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-payEPSS 0.3%CVE-2026-16575MEDIUMDokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST EndpointEPSS 0.3%CVE-2025-14973MEDIUMRecipe Card Blocks < 3.4.13 - Contributor+ SQLiEPSS 0.3%CVE-2026-7385MEDIUMDecent Comments < 3.0.2 - Unauthenticated Email Address DisclosureEPSS 0.3%CVE-2026-16612MEDIUMFiboSearch < 1.34.1 - Unauthenticated Password-Protected Product Information DisclosureEPSS 0.3%CVE-2026-86449MEDIUMLearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST APIEPSS 0.3%CVE-2026-78149MEDIUMPost Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_idEPSS 0.3%CVE-2026-19073MEDIUMOrder Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data DisclosureEPSS 0.3%CVE-2026-81197MEDIUMMasterStudy LMS < 3.7.46 - Unauthenticated Unpublished Course Title Disclosure via course-list REST RouteEPSS 0.3%CVE-2026-87916MEDIUMWPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII DisclosureEPSS 0.3%CVE-2026-87854MEDIUMSubscriptions for WooCommerce < 2.0.3 - Unauthenticated Subscription Data Disclosure via REST API Secret Key BypassEPSS 0.3%CVE-2026-18231MEDIUMWP Directory Kit < 1.5.7 - Unauthenticated User Email Disclosure via select_2_ajax_userEPSS 0.3%CVE-2026-81195MEDIUMMasterStudy LMS < 3.7.46 - Unauthenticated Student Enrollment Disclosure via student-courses REST RouteEPSS 0.3%CVE-2026-82124MEDIUMSchema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema OutputEPSS 0.3%CVE-2026-86445MEDIUMLearnPress < 4.4.7 - Unauthenticated Question Bank Disclosure via load_content_via_ajaxEPSS 0.3%CVE-2026-2696MEDIUMExport All URLs < 5.1 - Unauthenticated Sensitive Data ExposureEPSS 0.3%CVE-2024-5282MEDIUMWP Affiliate Platform < 6.5.1 - Reflected XSS via Registration FormEPSS 0.3%