Vulnerabilidades en Unknown

5585 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2022-4058—Photo Gallery < 1.8.3 - Stored XSS via CSRFEPSS 0.2%CVE-2025-3584MEDIUMNewsletter < 8.8.2 - Admin+ Stored XSS via SubscriptionEPSS 0.2%CVE-2025-10638MEDIUMNS Maintenance Mode for WP <= 1.3.1 - Unauthenticated Subscribers ExportEPSS 0.2%CVE-2026-10834MEDIUMWP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_imageEPSS 0.2%CVE-2026-93580MEDIUMInPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment WebhookEPSS 0.2%CVE-2026-84025LOWBEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOREPSS 0.2%CVE-2025-1627MEDIUMQi Blocks < 1.4 - Contributor+ Stored XSS via ToC BlockEPSS 0.2%CVE-2024-1232MEDIUMCM Download Manager < 2.9.0 - Download Deletion via CSRFEPSS 0.2%CVE-2025-1626MEDIUMQi Blocks < 1.4 - Contributor+ Stored XSS vi Countdown BlockEPSS 0.2%CVE-2026-12971LOWLearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply_image_featureEPSS 0.2%CVE-2026-80437MEDIUMNinja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge TagsEPSS 0.2%CVE-2026-15256MEDIUMNinja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field DefaultEPSS 0.2%CVE-2026-80439MEDIUMRedirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-TagsEPSS 0.2%CVE-2026-86813MEDIUMMetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-ToEPSS 0.2%CVE-2026-81571MEDIUMBrave Popup Builder < 0.8.8 - Unauthenticated Arbitrary Shortcode Execution via UTM ParameterEPSS 0.2%CVE-2026-80440MEDIUMHustle < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution via Success Message PlaceholdersEPSS 0.2%CVE-2026-78363MEDIUMMW WP Form < 5.1.5 - Unauthenticated Arbitrary Shortcode Execution via Completion Message Merge TagsEPSS 0.2%CVE-2026-14819LOWEvent Tickets < 5.28.4 - Editor+ Stored XSS via Ticket MoveEPSS 0.2%CVE-2026-8981LOWLazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTMLEPSS 0.2%CVE-2026-4512LOWWP reCaptcha by WebDesignBy < 2.0 – Admin+ Stored XSSEPSS 0.2%