Vulnerabilities in unknown

5,492 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2021-24201—Elementor < 3.1.2 - Authenticated Stored Cross-Site Scripting (XSS) in Column ElementEPSS 0.7%CVE-2023-0376MEDIUMQubely < 1.8.5 - Contributor+ Stored XSSEPSS 0.7%CVE-2023-3365HIGHMultiParcels Shipping For WooCommerce < 1.14.14 - Subscriber+ Arbitrary Shipment DeletionEPSS 0.7%CVE-2023-0069MEDIUMWPaudio MP3 Player <= 4.0.2 - Contributor+ Stored XSSEPSS 0.7%CVE-2022-0969—Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-2877—Titan Anti-spam & Security < 7.3.1 - Protection Bypass due to IP SpoofingEPSS 0.7%CVE-2022-1323—Discy < 5.0 - Subscriber+ Broken Access Control to change settingsEPSS 0.7%CVE-2024-6847CRITICALSmartSearch WP <= 2.4.4 - Unauthenticated SQLiEPSS 0.7%CVE-2023-1809HIGHDownload Manager Pro < 6.3.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.7%CVE-2022-2198—WPQA < 5.7 - Subscriber+ Private Message Disclosure via IDOREPSS 0.7%CVE-2023-1524MEDIUMDownload Manager < 3.2.71 - Broken Access ControlsEPSS 0.7%CVE-2021-24626—Chameleon CSS <= 1.2 - Subscriber+ SQL InjectionEPSS 0.7%CVE-2023-3139—Protect WP Admin < 4.0 - Unauthenticated Protection BypassEPSS 0.7%CVE-2021-24152—Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2026-16268HIGHNewsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerEPSS 0.7%CVE-2026-11974HIGHMedia folder Addon < 4.1.7 - Unauthenticated Arbitrary File DownloadEPSS 0.7%CVE-2026-16616HIGHSimple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path TraversalEPSS 0.7%CVE-2023-0441HIGHGallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options UpdateEPSS 0.7%CVE-2026-76552HIGHWP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image ImportEPSS 0.7%CVE-2026-16985HIGHSqueeze < 1.7.12 - Author+ Arbitrary File UploadEPSS 0.7%