Vulnerabilidades en Unknown
5576 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-82305MEDIUMYITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_titleEPSS 0.3%CVE-2026-13692MEDIUMPayU CommercePro < 3.9.0 - Unauthenticated Order TamperingEPSS 0.3%CVE-2026-12966MEDIUMDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX ActionsEPSS 0.3%CVE-2026-18779MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_bookedEPSS 0.3%CVE-2022-1780—LaTeX for WordPress <= 3.4.10 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-85350MEDIUMUpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought TogetherEPSS 0.3%CVE-2026-77013MEDIUMIcollect <= 1.0.0 - Unauthenticated User and Term Creation via Unrestricted Method DispatchEPSS 0.3%CVE-2026-16962MEDIUMTamara Checkout <= 1.9.9.20 - Unauthenticated Order Status ManipulationEPSS 0.3%CVE-2026-87966MEDIUMEasy Appointments 4.0 - 4.0.2.1 - Unauthenticated Arbitrary Appointment Modification and Deletion via IDOREPSS 0.3%CVE-2025-14829CRITICALe-xact-hosted-payment <= 2.0 - Unauthenticated Arbitrary File DeletionEPSS 0.3%CVE-2026-15229MEDIUMPinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price ManipulationEPSS 0.3%CVE-2026-88910MEDIUMKBoard < 6.7 - Unauthenticated Board Media Deletion via IDOREPSS 0.3%CVE-2026-92435MEDIUMMailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST APIEPSS 0.3%CVE-2022-1787—Sideblog <= 6.0 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-18777MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Change via update_appointment_statusEPSS 0.3%CVE-2022-1792—Quick Subscribe <= 1.7.1 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-13143MEDIUMWP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPNEPSS 0.3%CVE-2026-77689MEDIUMAmelia Pro 9.0 - 9.8 - Unauthenticated Payment BypassEPSS 0.3%CVE-2022-1818—Multi-page Toolkit <= 2.6 - Arbitrary Settings Update to Stored XSS via CSRFEPSS 0.3%CVE-2026-79630MEDIUMWPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID SubstitutionEPSS 0.3%