Vulnerabilidades en Unknown
5518 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-16057MEDIUMContest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_libraryEPSS 0.4%CVE-2026-19714CRITICALSimple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience ValidationEPSS 0.4%CVE-2026-15210CRITICALLogin/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeover via OTP Brute ForceEPSS 0.4%CVE-2023-2707MEDIUMAppointment booking addon for Gravity Forms <= 1.9.5.1 - Admin+ Stored XSSEPSS 0.4%CVE-2026-19077MEDIUMCopy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Level AuthorizationEPSS 0.4%CVE-2026-13332CRITICALMasteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)EPSS 0.4%CVE-2024-2376HIGHWPQA < 6.1.1 - Arbitrary Category and Tag Follow/Unfollow via CSRFEPSS 0.4%CVE-2026-8157HIGHVitepos < 3.4.2 - Outlet Manager+ Privilege EscalationEPSS 0.4%CVE-2024-4269MEDIUMSVG Block < 1.1.20 - Author+ Stored XSS via SVG File UploadEPSS 0.4%CVE-2026-76547MEDIUMProfile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/ExportEPSS 0.4%CVE-2024-1106MEDIUMShariff Wrapper < 4.6.10 - Admin+ Stored XSSEPSS 0.4%CVE-2026-12525HIGHRedux Framework < 4.5.13 - Subscriber+ Privilege Escalation to AdministratorEPSS 0.4%CVE-2026-87759HIGHAdd User Autocomplete < 1.2 - Subscriber+ Privilege EscalationEPSS 0.4%CVE-2026-88904HIGHPuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege EscalationEPSS 0.4%CVE-2024-10562LOWForm Maker by 10Web < 1.15.31 - Admin+ Stored XSSEPSS 0.4%CVE-2026-16594HIGHWP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key DisclosureEPSS 0.4%CVE-2024-6076MEDIUMWP eStore < 8.5.5 - Reflected XSS in Category EditingEPSS 0.4%CVE-2024-11184MEDIUMWP Enabled SVG <= 0.7 - Author+ Stored XSS via SVGEPSS 0.4%CVE-2024-1401MEDIUMProfile Box Shortcode And Widget < 1.2.1 Admin+ Stored XSSEPSS 0.4%CVE-2026-17542HIGHBit File Manager < 6.9.1 - Subscriber+ Sensitive Data Disclosure via bitapps_fm_connectorEPSS 0.4%