Vulnerabilidades en Unknown
5615 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-0658MEDIUMFive Star Restaurant Reservations < 2.7.9 - Arbitrary Bookings Deletion via CSRFEPSS 0.2%CVE-2026-10827LOWSpectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block AttributesEPSS 0.2%CVE-2026-91025MEDIUMBooking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOREPSS 0.2%CVE-2026-92422MEDIUMMeow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST RouteEPSS 0.2%CVE-2026-86839LOWBookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via IDOREPSS 0.2%CVE-2026-86824MEDIUMNewsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature KeyEPSS 0.2%CVE-2026-85004MEDIUMPopup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connectEPSS 0.2%CVE-2026-74916MEDIUMWP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeyed Tracking ParametersEPSS 0.2%CVE-2026-93510MEDIUMPoints and Rewards for WooCommerce < 2.10.4 - Subscriber+ Arbitrary Points and Wallet Balance Manipulation via assign_claim_pointsEPSS 0.2%CVE-2026-88845MEDIUMMasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo ImportEPSS 0.2%CVE-2026-85576MEDIUMAll in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings UpdateEPSS 0.2%CVE-2026-88847MEDIUMMasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record CreationEPSS 0.2%CVE-2026-15384MEDIUMManual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOREPSS 0.2%CVE-2025-12685MEDIUMWPBookit <= 1.0.7 - Customer Deletion via CSRFEPSS 0.1%CVE-2023-3360LOWWeaver Show Posts < 1.8.1 - Admin+ PHP Object InjectionEPSS 0.1%CVE-2026-78393MEDIUMLink Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb LinksEPSS 0.1%CVE-2026-19220LOWForminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege EscalationEPSS 0.1%CVE-2026-89303MEDIUMPost Voting System <= 1.0 - Subscriber+ SQLi via 'row' ParameterEPSS 0.1%CVE-2026-16569MEDIUMShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock UpdateEPSS 0.1%CVE-2026-14566MEDIUMAdvanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata TamperingEPSS 0.1%