Vulnerabilities in Unknown

5,591 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-86812MEDIUMWPCafe 3.0.10 - 3.0.17 - Unauthenticated Order Disclosure and Modification via food-orders REST APIEPSS 0.3%CVE-2026-14845MEDIUMNewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post WidgetEPSS 0.3%CVE-2026-2811MEDIUMAjaxify Comments < 3.2 - Unauthenticated HTTP Header InjectionEPSS 0.3%CVE-2026-90923MEDIUMAutopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and DeletionEPSS 0.3%CVE-2026-17019MEDIUMJetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)EPSS 0.3%CVE-2026-11965MEDIUMUser Registration & Membership < 5.2.0 - Unauthenticated Paid Membership BypassEPSS 0.3%CVE-2026-12982MEDIUMDocument Gallery < 5.1.1 - Reflected XSS via dg_generate_galleryEPSS 0.3%CVE-2026-77695MEDIUMWoo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and ManipulationEPSS 0.3%CVE-2026-18037MEDIUMCreate by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and PublicationEPSS 0.3%CVE-2026-14834MEDIUMMailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAXEPSS 0.3%CVE-2026-77010MEDIUMHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Join URL Disclosure and Class Access Code BypassEPSS 0.3%CVE-2026-16032MEDIUMLWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User MonitoringEPSS 0.3%CVE-2024-13874HIGHFeedify – Web Push Notifications < 2.4.6 - Reflected XSSEPSS 0.3%CVE-2025-1033MEDIUMBadgearoo <= 1.0.14 - Admin+ Stored XSSEPSS 0.3%CVE-2026-14190MEDIUMSina Extension for Elementor < 3.10.2 - Reflected XSSEPSS 0.3%CVE-2026-10525MEDIUMNEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form SubmissionEPSS 0.3%CVE-2026-17565HIGHAnimation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request ForgeryEPSS 0.3%CVE-2026-4432MEDIUMYITH WooCommerce Wishlist < 4.13.0 - Unauthenticated Arbitrary Wishlist Renaming via IDOREPSS 0.3%CVE-2026-85009MEDIUMRestroPress <= 3.4.6 - Unauthenticated Order Enumeration and Order Note Modification via Payment RecoveryEPSS 0.3%CVE-2026-5776MEDIUMEmail Encoder < 2.4.7 - Unauthenticated Stored XSSEPSS 0.3%