Vulnerabilities in Unknown
5,585 resultsVexday analysis
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-77702MEDIUMEventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_tokenEPSS 0.3%CVE-2026-11966MEDIUMUser Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription HandlerEPSS 0.3%CVE-2026-75798MEDIUMAI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor AssistantEPSS 0.3%CVE-2026-12966MEDIUMDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX ActionsEPSS 0.3%CVE-2026-14305MEDIUMWP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likesEPSS 0.3%CVE-2026-79630MEDIUMWPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID SubstitutionEPSS 0.3%CVE-2026-17021MEDIUMSalon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total TamperingEPSS 0.3%CVE-2026-77689MEDIUMAmelia Pro 9.0 - 9.8 - Unauthenticated Payment BypassEPSS 0.3%CVE-2026-14842MEDIUMEvents Made Easy < 3.1.2 - Unauthenticated Payment BypassEPSS 0.3%CVE-2022-1780—LaTeX for WordPress <= 3.4.10 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-13143MEDIUMWP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPNEPSS 0.3%CVE-2022-1818—Multi-page Toolkit <= 2.6 - Arbitrary Settings Update to Stored XSS via CSRFEPSS 0.3%CVE-2026-85037MEDIUMSunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOREPSS 0.3%CVE-2022-1792—Quick Subscribe <= 1.7.1 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2022-1763—Static Page eXtended <= 2.1 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-84936MEDIUMEmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database BloatEPSS 0.3%CVE-2026-81424MEDIUMAccept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOREPSS 0.3%CVE-2026-91827HIGHNinja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV ExportEPSS 0.3%CVE-2025-14829CRITICALe-xact-hosted-payment <= 2.0 - Unauthenticated Arbitrary File DeletionEPSS 0.3%CVE-2026-85038MEDIUMB2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role SelectionEPSS 0.3%