Vulnerabilidades en Unknown
5576 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-85038MEDIUMB2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registration Role SelectionEPSS 0.3%CVE-2026-91827HIGHNinja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV ExportEPSS 0.3%CVE-2022-1759—RB Internal Links <= 2.0.16 - Stored Cross-Site Scripting via CSRFEPSS 0.3%CVE-2026-79632MEDIUMWPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode_optin_submissionEPSS 0.3%CVE-2026-75798MEDIUMAI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor AssistantEPSS 0.3%CVE-2022-1763—Static Page eXtended <= 2.1 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-91015MEDIUMMaster Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expiredEPSS 0.3%CVE-2026-77701MEDIUMWCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest OrdersEPSS 0.3%CVE-2026-88910MEDIUMKBoard < 6.7 - Unauthenticated Board Media Deletion via IDOREPSS 0.3%CVE-2022-1780—LaTeX for WordPress <= 3.4.10 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-18779MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Appointment and Payment Record Deletion via update_appointment_bookedEPSS 0.3%CVE-2026-13328MEDIUMTLP Food Menu < 6.0.2 - Unauthenticated Reservation Status ModificationEPSS 0.3%CVE-2026-15237MEDIUMHotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST EndpointEPSS 0.3%CVE-2026-77702MEDIUMEventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_tokenEPSS 0.3%CVE-2026-85037MEDIUMSunshine Photo Cart < 3.7 - Unauthenticated Price Manipulation via IDOREPSS 0.3%CVE-2026-12966MEDIUMDirect Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX ActionsEPSS 0.3%CVE-2022-1764—WP-chgFontSize <= 1.8 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2022-1792—Quick Subscribe <= 1.7.1 - Arbitrary Settings Update via CSRF to Stored XSSEPSS 0.3%CVE-2026-85350MEDIUMUpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought TogetherEPSS 0.3%CVE-2026-79630MEDIUMWPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID SubstitutionEPSS 0.3%