Vulnerabilidades en Unknown
5520 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-18470HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password ResponseEPSS 0.4%CVE-2026-15048HIGHGeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat HistoryEPSS 0.4%CVE-2026-18032HIGHWP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization BypassEPSS 0.4%CVE-2026-19717HIGHCatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST APIEPSS 0.4%CVE-2026-77007HIGHHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret DisclosureEPSS 0.4%CVE-2026-11571HIGHEverest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV ArtifactsEPSS 0.4%CVE-2026-80494HIGHYogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File DownloadEPSS 0.4%CVE-2026-13154HIGHEssential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries EndpointEPSS 0.4%CVE-2026-16602HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST EndpointEPSS 0.4%CVE-2026-18050HIGHEvents Manager < 7.4 - Unauthenticated Pending Upload Disclosure via events-manager/v1/uploadsEPSS 0.4%CVE-2026-16604HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Content-Lock Block data-content AttributeEPSS 0.4%CVE-2026-18049HIGHWP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogoEPSS 0.4%CVE-2026-14839HIGHMapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content DisclosureEPSS 0.4%CVE-2026-16603HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST APIEPSS 0.4%CVE-2026-15236HIGHGallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token DisclosureEPSS 0.4%CVE-2026-92404HIGHMgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential DisclosureEPSS 0.4%CVE-2026-16988HIGHGeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST EndpointEPSS 0.4%CVE-2021-24688—Orange Form <= 1.0.1 - Unauthenticated Arbitrary Post DeletionEPSS 0.4%CVE-2023-4035MEDIUMSimple Blog Card < 1.31 - Contributor+ Stored XSS via ShortcodeEPSS 0.4%CVE-2022-4946MEDIUMFrontend Post WordPress Plugin <= 2.8.4 - Contributor+ Arbitrary RedirectEPSS 0.4%