Vulnerabilities in Unknown

5,615 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-16574MEDIUMDokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST EndpointEPSS 0.2%CVE-2026-14310MEDIUMTutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply InjectionEPSS 0.2%CVE-2026-14224MEDIUMEasy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOREPSS 0.2%CVE-2026-85133MEDIUMWPLP Cookie Consent < 4.4.2 - Subscriber+ Missing Authorization via Multiple Settings AJAX ActionsEPSS 0.2%CVE-2026-15238MEDIUMHotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOREPSS 0.2%CVE-2026-74929MEDIUMWP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOREPSS 0.2%CVE-2025-9540MEDIUMMarkup Markdown < 3.20.10 - Contributor+ Stored XSSEPSS 0.2%CVE-2026-14941MEDIUMCustomer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorization via Multiple Settings AJAX ActionsEPSS 0.2%CVE-2026-16064MEDIUMEvent Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_eventEPSS 0.2%CVE-2026-12689MEDIUMProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing AuthorizationEPSS 0.2%CVE-2024-3972MEDIUMSimilarity <= 3.0 - Stored XSS via CSRFEPSS 0.2%CVE-2026-14926MEDIUMFluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOREPSS 0.2%CVE-2024-6853MEDIUMWP MultiTasking <= 0.1.12 - Welcome Popup Update via CSRFEPSS 0.2%CVE-2024-8047MEDIUMVisual Sound (old) <= 1.06 - Settings Update via CSRFEPSS 0.2%CVE-2023-0420MEDIUMCustom Post Type and Taxonomy GUI Manager <= 1.1 - Stored XSS via CSRFEPSS 0.2%CVE-2026-19226MEDIUMRoyal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Effect SettingsEPSS 0.2%CVE-2026-14835MEDIUMSOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Post MetaboxEPSS 0.2%CVE-2025-5035MEDIUMFirelight Lightbox < 2.3.16 - Contributor+ Stored XSSEPSS 0.2%CVE-2025-5093MEDIUMResponsive Lightbox & Gallery < 2.5.2 - Contributor+ Stored XSSEPSS 0.2%CVE-2024-3471LOWButton Generator < 3.0 - Button Deletion via CSRFEPSS 0.2%