Vulnerabilities in unknown

5,533 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2026-12721HIGHKirki < 6.0.13 - Unauthenticated SQL InjectionEPSS 0.4%CVE-2026-87770HIGHPrice Drop Alert for WooCommerce <= 1.1 - Unauthenticated SQL Injection via productEPSS 0.4%CVE-2026-87963HIGHYo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username ParameterEPSS 0.4%CVE-2026-84750MEDIUMUltimate Addons for Contact Form 7 3.2.4 - 3.5.50 - Unauthenticated Arbitrary File Upload via Signature FieldEPSS 0.4%CVE-2026-12512HIGHQuotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc ParameterEPSS 0.4%CVE-2026-6379HIGHWP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' ParameterEPSS 0.4%CVE-2026-12582HIGHLibrary Management System < 3.5.8 - Unauthenticated SQL Injection via book_idEPSS 0.4%CVE-2026-87774HIGHTz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQL Injection via weekEPSS 0.4%CVE-2026-87771HIGHProduct Question and Answer <= 1.1.0 - Unauthenticated SQL Injection via p_id and readEPSS 0.4%CVE-2026-16950HIGHProduct Shortlist <= 1.0.4 - Unauthenticated SQL Injection via get_shortlisted_productsEPSS 0.4%CVE-2026-82304HIGHMusic Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data HandlerEPSS 0.4%CVE-2026-87767HIGHWP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via urlEPSS 0.4%CVE-2026-87775HIGHTz Weekly Radio Schedule <= 1.8.1 - Unauthenticated SQLi via tzwrs_update_cellEPSS 0.4%CVE-2026-17044HIGHWordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadidEPSS 0.4%CVE-2026-8082HIGHBpost Shipping Platform < 3.2.3 - Unauthenticated SQL InjectionEPSS 0.4%CVE-2026-84047HIGHAlbum Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_actionEPSS 0.4%CVE-2026-11590HIGHWP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array KeysEPSS 0.4%CVE-2026-11349HIGHModern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_moreEPSS 0.4%CVE-2026-3830HIGHProduct Filter for WooCommerce by WBW < 3.1.3 - Unauthenticated SQLiEPSS 0.4%CVE-2026-80491HIGHSAMO Forms <= 1.0.0 - Unauthenticated SQLiEPSS 0.4%