Vulnerabilities in Unknown

5,585 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2024-10818MEDIUMJSFiddle Shortcode < 1.1.3 - Contributor+ XSS via ShortcodeEPSS 0.3%CVE-2024-9645MEDIUMPost Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSSEPSS 0.3%CVE-2024-11841MEDIUMTithe.ly Giving Button <= 1.1 - Contributor+ Stored XSS via ShortcodeEPSS 0.3%CVE-2026-14216MEDIUMAmelia < 2.4.7 - Unauthenticated Notification Queue DispatchEPSS 0.3%CVE-2024-9662MEDIUMCYAN Backup < 2.5.3 - Admin+ Stored XSS via General SettingsEPSS 0.3%CVE-2026-14215MEDIUMAmelia < 2.4.9 - Unauthenticated Post-Booking Action TriggerEPSS 0.3%CVE-2024-13095MEDIUMWP Triggers Lite <= 2.5.3 - Admin+ SQL InjectionEPSS 0.3%CVE-2025-15671MEDIUMWelcart e-Commerce < 2.12.1 - Session Fixation via uscesid ParameterEPSS 0.3%CVE-2024-7713HIGHAI Chatbot with ChatGPT by AYS <= 2.0.9 - Unauthenticated OpenAI Key DisclosureEPSS 0.3%CVE-2024-8854MEDIUMPolls CP <= 1.0.75 - Admin+ Stored XSS via Custom StylesEPSS 0.3%CVE-2022-1787—Sideblog <= 6.0 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-18779MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_bookedEPSS 0.3%CVE-2026-14322MEDIUMTimetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_methodEPSS 0.3%CVE-2022-1781—postTabs <= 2.10.6 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-90922MEDIUMPaid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency MismatchEPSS 0.3%CVE-2022-1764—WP-chgFontSize <= 1.8 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-13328MEDIUMTLP Food Menu < 6.0.2 - Unauthenticated Reservation Status ModificationEPSS 0.3%CVE-2026-79632MEDIUMWPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submissionEPSS 0.3%CVE-2026-90976MEDIUMClean Login < 1.19 - Unauthenticated Account Creation with Registration DisabledEPSS 0.3%CVE-2026-87966MEDIUMEasy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOREPSS 0.3%