Vulnerabilities in unknown
5,518 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2026-85122HIGHEasy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Stored XSS via Form Type ConfusionEPSS 0.5%CVE-2026-11855HIGHSimple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API VersionEPSS 0.5%CVE-2026-11589HIGHWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File UploadEPSS 0.5%CVE-2026-81742HIGHBE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget ManipulationEPSS 0.5%CVE-2026-10081HIGHUnlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews WidgetEPSS 0.5%CVE-2026-88825HIGHiGMS Direct Booking < 2.0 - Unauthenticated Stored XSS via Widget SettingsEPSS 0.5%CVE-2026-87786HIGHDewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout CoordinatesEPSS 0.5%CVE-2026-11767HIGHCRT Addons for Elementor < 1.6.7 - Unauthenticated Stored XSS via Contact FormEPSS 0.5%CVE-2026-12968HIGHProduct Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG UploadEPSS 0.5%CVE-2024-9828MEDIUMTaskbuilder < 3.0.5 - Admin+ SQL InjectionEPSS 0.5%CVE-2021-24570—Paypal Donation < 1.3.1 - CSRF to Stored Cross-Site ScriptingEPSS 0.5%CVE-2023-0274—URL Params < 2.5 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-2028—Call Now Accessibility Button < 1.1 - Admin+ Stored Cross Site ScriptingEPSS 0.5%CVE-2023-0272MEDIUMNEX-Forms < 8.3.3 - Contributor+ Stored XSSEPSS 0.5%CVE-2022-4431MEDIUMWOOCS < 1.3.9.4 - Contributor+ Stored XSSEPSS 0.5%CVE-2024-13925HIGHKlarna Checkout for WooCommerce < 2.13.5 - DoS via Excessive LoggingEPSS 0.5%CVE-2023-0604MEDIUMWP Food Manager < 1.0.4 - Admin+ Stored XSSEPSS 0.5%CVE-2023-0537MEDIUMProduct Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSSEPSS 0.5%CVE-2024-11223MEDIUMWPForms < 1.9.2.3 - Admin+ Stored XSSEPSS 0.5%CVE-2026-74933HIGHGenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration OverwriteEPSS 0.5%