Vulnerabilidades en Roxnor
89 resultadosAnálisis Vexday
Roxnor apresenta um perfil de risco moderado com 17 vulnerabilidades catalogadas, sendo apenas 1 crítica e nenhuma sob exploração ativa documentada. A fraqueza dominante é falta de autorização (CWE-862), com 2 novos CVEs nos últimos 90 dias, indicando descobertas recentes mas sem urgência de resposta imediata.
CVE-2023-0695MEDIUMMetform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf shortcodeEPSS 0.4%CVE-2023-2517MEDIUMMetform Elementor Contact Form Builder <= 3.3.2 - Cross-Site Request Forgery via permalink_setupEPSS 0.4%CVE-2024-6455MEDIUMElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content FunctionEPSS 0.4%CVE-2023-0710MEDIUMMetform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf_thankyou shortcodeEPSS 0.4%CVE-2025-10862HIGHPopup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id'EPSS 0.4%CVE-2025-10861HIGHPopup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 - Unauthenticated Server-Side Request ForgeryEPSS 0.4%CVE-2026-2879MEDIUMGetGenie <= 4.3.2 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Post Overwrite/DeletionEPSS 0.4%CVE-2024-1239MEDIUMElementsKit Elementor addons <= 3.0.4 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-57316MEDIUMWordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-13620MEDIUMWp Social Login and Register Social Counter <= 3.1.3 - Missing Authorization in Cache REST Endpoints to Social Counter TamperingEPSS 0.4%CVE-2026-59560MEDIUMWordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2026-75930MEDIUMFundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' ParameterEPSS 0.4%CVE-2025-60106MEDIUMWordPress EmailKit Plugin <= 1.6.0 - Arbitrary Content Deletion VulnerabilityEPSS 0.4%CVE-2025-1005MEDIUMElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion WidgetEPSS 0.4%CVE-2024-37255MEDIUMWordPress ElementsKit Lite plugin <= 3.1.4 - Unauthenticated Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-1238MEDIUMElementsKit Elementor addons <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-76063MEDIUMFundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' ParameterEPSS 0.3%CVE-2024-2803MEDIUMElementsKit Elementor addons <= 3.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown WidgetEPSS 0.3%CVE-2026-57406MEDIUMWordPress FundEngine plugin <= 1.7.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-2791MEDIUMMetform Elementor Contact Form Builder <= 3.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via WidgetsEPSS 0.3%