Vulnerabilidades en Unknown
5582 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-13415HIGHCMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settingsEPSS 0.2%CVE-2025-2560MEDIUMNinja Forms < 3.10.1 - Admin+ Stored XSSEPSS 0.2%CVE-2025-2561MEDIUMNinja Forms < 3.10.1 - Admin+ Stored XSSEPSS 0.2%CVE-2026-86802LOWTo Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via ImportEPSS 0.2%CVE-2026-11563CRITICALWord Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path TraversalEPSS 0.2%CVE-2026-84907LOWEventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST EndpointEPSS 0.2%CVE-2025-3662MEDIUMFancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSSEPSS 0.2%CVE-2023-6029HIGHEazyDocs < 2.3.6 - Unauthenticated Arbitrary Posts Deletion and Document ManagementEPSS 0.2%CVE-2023-7269HIGHArtPlacer Widget < 2.21.2 - Stored XSS via CSRFEPSS 0.2%CVE-2026-14550MEDIUMWPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing AuthorizationEPSS 0.2%CVE-2023-2627—KiviCare Management System < 3.2.1 - Subscriber+ Unauthorised AJAX CallsEPSS 0.2%CVE-2025-5125MEDIUMCustom Post Carousels with Owl < 1.4.12 - Contributor+ Stored XSSEPSS 0.2%CVE-2026-19454MEDIUMJetBackup 3.1.18.8 - 3.1.23.3 - Admin+ Multisite Network Backup DownloadEPSS 0.2%CVE-2023-1414MEDIUMWP VR < 8.3.0 - Subscriber+ Arbitrary Tour UpdateEPSS 0.2%CVE-2025-1485MEDIUMReal Cookie Banner < 5.1.6 - Admin+ Stored XSSEPSS 0.2%CVE-2026-13413MEDIUMCMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL MatchEPSS 0.2%CVE-2025-13029HIGHKnowband Mobile App Builder for wooCommerce < 3.0.0 – Unauthenticated Arbitrary User DeletionEPSS 0.2%CVE-2024-2429MEDIUMSalon booking system <= 9.6.5 - Settings Update via CSRFEPSS 0.2%CVE-2025-10638MEDIUMNS Maintenance Mode for WP <= 1.3.1 - Unauthenticated Subscribers ExportEPSS 0.2%CVE-2025-4567MEDIUMPost Slider and Carousel with Widget < 3.2.10 - Admin+ Stored XSSEPSS 0.2%