Vulnerabilities in unknown
5,533 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2023-2503MEDIUM10WebSocial < 1.2.9 - Reflected XSSEPSS 0.5%CVE-2023-3954MEDIUMMultiParcels Shipping For WooCommerce 1.15.2-1.15.3 - Reflected XSSEPSS 0.5%CVE-2023-2572MEDIUMSurvey Maker < 3.4.7 - Reflected XSSEPSS 0.5%CVE-2023-0540MEDIUMGS Filterable Portfolio < 1.6.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-0559MEDIUMGS Portfolio for Envato < 1.4.0 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-0372MEDIUMEmbedStories < 0.7.5 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-13596CRITICALParticipants Database < 2.7.8.4 - Unauthenticated SQL Injection via List SearchEPSS 0.5%CVE-2026-12965CRITICALSuper Store Finder < 7.11 - Unauthenticated SQL Injection via ssf_trackingEPSS 0.5%CVE-2026-16623HIGHCreate Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)EPSS 0.5%CVE-2023-0285—Real Media Library < 4.18.29 - Author+ Stored XSSEPSS 0.5%CVE-2023-0380MEDIUMEasy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-16532CRITICALLink Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission FormEPSS 0.5%CVE-2023-0492MEDIUMGS Products Slider for WooCommerce < 1.5.9 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-15360CRITICALAjax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_argsEPSS 0.5%CVE-2023-0823MEDIUMCookie Notice & Compliance for GDPR / CCPA < 2.4.7 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-18473CRITICALWP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' ParameterEPSS 0.5%CVE-2024-0820MEDIUMJobs for WordPress < 2.7.4 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-12713CRITICALWPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_numberEPSS 0.5%CVE-2023-0371MEDIUMEmbedSocial < 1.1.28 - Contributor+ Stored XSSEPSS 0.5%CVE-2022-4714MEDIUMWP Dark Mode < 4.0.0 - Contributor+ Stored XSS in ShortcodeEPSS 0.5%