Vulnerabilidades en Unknown
5585 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2024-9689MEDIUMPost From Frontend <= 1.0.0 - Post Deletion via CSRFEPSS 0.2%CVE-2026-81651LOWNextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOREPSS 0.2%CVE-2026-81654LOWNextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings UpdateEPSS 0.2%CVE-2026-16983MEDIUMGutentor < 4.0.6 - Subscriber+ Password Protected Post Password Disclosure via REST APIEPSS 0.2%CVE-2023-3666LOWSticky Side Buttons < 2.0.0 - Admin+ Stored XSSEPSS 0.2%CVE-2026-96532HIGHTestimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post UpdateEPSS 0.2%CVE-2026-19436HIGHUltimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation via Discounted PurchaseEPSS 0.2%CVE-2024-6224MEDIUMSend email only on Reply to My Comment <= 1.0.6 - Stored XSS via CSRFEPSS 0.2%CVE-2026-94298MEDIUMBuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content ParameterEPSS 0.2%CVE-2023-7083MEDIUMVoting Record <= 2.0 - Settings Update to Stored XSS via CSRFEPSS 0.2%CVE-2024-3058MEDIUMENL Newsletter <= 1.0.1 - Stored XSS via CSRFEPSS 0.2%CVE-2025-8945MEDIUMWp Edit Password Protected < 1.3.5 - Protection Bypass via REST APIEPSS 0.2%CVE-2026-86832MEDIUMMetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST APIEPSS 0.2%CVE-2025-12954LOWTimetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOREPSS 0.2%CVE-2026-94274MEDIUMYayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST APIEPSS 0.2%CVE-2026-88929MEDIUMSale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product DisclosureEPSS 0.2%CVE-2026-90950MEDIUMPaid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration FormEPSS 0.2%CVE-2026-86789MEDIUMConnections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST RoutesEPSS 0.2%CVE-2026-90985MEDIUMWPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Description Disclosure via woosc_loadEPSS 0.2%CVE-2026-96886MEDIUMCourse Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV ExportEPSS 0.2%