Vulnerabilidades en Unknown
5533 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-88995MEDIUMBookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability CheckEPSS 0.3%CVE-2026-19073MEDIUMOrder Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data DisclosureEPSS 0.3%CVE-2026-87916MEDIUMWPBot 8.4.9 - 8.5.9 - Unauthenticated Chat Visitor PII DisclosureEPSS 0.3%CVE-2026-77754MEDIUMKirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_apisEPSS 0.3%CVE-2026-86800MEDIUMWP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility CheckEPSS 0.3%CVE-2026-86449MEDIUMLearnPress < 4.4.7 - Unauthenticated Unpublished Course Disclosure via REST APIEPSS 0.3%CVE-2026-86447MEDIUMLearnPress < 4.4.7 - Unauthenticated Student Enrollment Disclosure via load_content_via_ajaxEPSS 0.3%CVE-2021-24730—Logo Showcase with Slick Slider < 1.2.5 - Subscriber+ Arbitrary Media Title/Description/Alt Text/URL UpdateEPSS 0.3%CVE-2024-7769MEDIUMWordpress Clicksold IDX Plugin <= 1.90 - Admin+ XSSEPSS 0.3%CVE-2022-1757—Pagebar < 2.70 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2024-11221MEDIUMFull Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSSEPSS 0.3%CVE-2022-0363—myCred < 2.4.4 - Subscriber+ Arbitrary Post CreationEPSS 0.3%CVE-2023-1330MEDIUMRedirection < 1.1.4 - Redirect Creation via CSRFEPSS 0.3%CVE-2026-15359MEDIUMTemplately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection OverwriteEPSS 0.3%CVE-2024-13116LOWCrelly Slider < 1.4.7 - Admin+ Stored XSSEPSS 0.3%CVE-2022-3880MEDIUMAntiHacker < 4.20 - Subscriber+ Arbitrary Plugin InstallationEPSS 0.3%CVE-2026-13694MEDIUMBit Form < 3.1.0 - Unauthenticated Workflow Trigger via Authentication BypassEPSS 0.3%CVE-2026-92099MEDIUMWPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias SquattingEPSS 0.3%CVE-2026-14568MEDIUMWP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment DeletionEPSS 0.3%CVE-2026-14816MEDIUMThe GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Requests SpamEPSS 0.3%