Vulnerabilidades en Unknown
5492 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2023-4270MEDIUMMin Max Control < 4.6 - Reflected XSSEPSS 0.5%CVE-2023-1377MEDIUMSolidres <= 0.9.4 - Multiple Reflected XSSEPSS 0.5%CVE-2023-3671MEDIUMMultiParcels Shipping For WooCommerce < 1.15.4 - Reflected XSSEPSS 0.5%CVE-2023-3041MEDIUMAutochat <= 1.1.7- Unauthenticated Stored XSSEPSS 0.5%CVE-2026-12965CRITICALSuper Store Finder < 7.11 - Unauthenticated SQL Injection via ssf_trackingEPSS 0.5%CVE-2022-4714MEDIUMWP Dark Mode < 4.0.0 - Contributor+ Stored XSS in ShortcodeEPSS 0.5%CVE-2026-16623HIGHCreate Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite)EPSS 0.5%CVE-2023-0371MEDIUMEmbedSocial < 1.1.28 - Contributor+ Stored XSSEPSS 0.5%CVE-2024-0820MEDIUMJobs for WordPress < 2.7.4 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-12713CRITICALWPCargo Track & Trace < 8.0.4 - Unauthenticated SQL Injection via wpcargo_tracking_numberEPSS 0.5%CVE-2023-0559MEDIUMGS Portfolio for Envato < 1.4.0 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-0372MEDIUMEmbedStories < 0.7.5 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-0540MEDIUMGS Filterable Portfolio < 1.6.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-13596CRITICALParticipants Database < 2.7.8.4 - Unauthenticated SQL Injection via List SearchEPSS 0.5%CVE-2023-0492MEDIUMGS Products Slider for WooCommerce < 1.5.9 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-0823MEDIUMCookie Notice & Compliance for GDPR / CCPA < 2.4.7 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-16532CRITICALLink Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission FormEPSS 0.5%CVE-2023-0285—Real Media Library < 4.18.29 - Author+ Stored XSSEPSS 0.5%CVE-2023-0380MEDIUMEasy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-18473CRITICALWP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' ParameterEPSS 0.5%