Vulnerabilities in Unknown

5,582 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-79631MEDIUMWPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Log FilesEPSS 0.3%CVE-2026-86447MEDIUMLearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajaxEPSS 0.3%CVE-2026-11351MEDIUMShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information DisclosureEPSS 0.3%CVE-2026-18778MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX ActionsEPSS 0.3%CVE-2026-84222MEDIUMKirki 6.2.1 - 6.2.5 - Unauthenticated Non-Public Post Content Disclosure via 'kirki_data' ParameterEPSS 0.3%CVE-2026-78151MEDIUMFormLayer < 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Submission ResponseEPSS 0.3%CVE-2026-86800MEDIUMWP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility CheckEPSS 0.3%CVE-2026-77782MEDIUMRank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txtEPSS 0.3%CVE-2021-24730—Logo Showcase with Slick Slider < 1.2.5 - Subscriber+ Arbitrary Media Title/Description/Alt Text/URL UpdateEPSS 0.3%CVE-2023-1330MEDIUMRedirection < 1.1.4 - Redirect Creation via CSRFEPSS 0.3%CVE-2022-0363—myCred < 2.4.4 - Subscriber+ Arbitrary Post CreationEPSS 0.3%CVE-2022-1757—Pagebar < 2.70 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2024-7769MEDIUMWordpress Clicksold IDX Plugin <= 1.90 - Admin+ XSSEPSS 0.3%CVE-2024-11221MEDIUMFull Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSSEPSS 0.3%CVE-2026-92099MEDIUMWPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias SquattingEPSS 0.3%CVE-2024-13116LOWCrelly Slider < 1.4.7 - Admin+ Stored XSSEPSS 0.3%CVE-2026-14816MEDIUMThe GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests SpamEPSS 0.3%CVE-2026-14568MEDIUMWP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment DeletionEPSS 0.3%CVE-2026-87891MEDIUMRox Appointment Booking < 1.2.0 - Unauthenticated Holiday Schedule Modification via REST APIEPSS 0.3%CVE-2026-13694MEDIUMBit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication BypassEPSS 0.3%