Vulnerabilidades en Unknown

5615 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-91017LOWRobokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT CallbackEPSS 0.1%CVE-2026-18044LOWEstatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value MismatchEPSS 0.1%CVE-2026-94271MEDIUMDeema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverified Success ReturnEPSS 0.1%CVE-2026-89289MEDIUMFast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update REST EndpointEPSS 0.1%CVE-2026-94270MEDIUMDeema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via WebhookEPSS 0.1%CVE-2026-96524HIGHMCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRFEPSS 0.1%CVE-2026-91023LOWMotors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featuredEPSS 0.1%CVE-2026-87069LOWForminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripeEPSS 0.1%CVE-2026-93507LOWWC Fields Factory < 4.1.11 - Contributor+ Arbitrary Post Cloning and Private Content DisclosureEPSS 0.1%CVE-2026-16292MEDIUMFrontend File Manager Plugin <= 23.6 - File Metadata Update via CSRFEPSS 0.1%CVE-2026-94278MEDIUMFile Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compatEPSS 0.1%CVE-2026-101147HIGHFeatured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRFEPSS 0.1%CVE-2026-81429HIGHExport & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRFEPSS 0.1%CVE-2026-14565MEDIUMAdvanced Customized Prompts <= 1.0.1 - Subscriber+ Stored XSS via Product Popup ConfigurationEPSS 0.1%CVE-2026-10724MEDIUMReviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google ReviewsEPSS 0.1%CVE-2025-6790MEDIUMQSM < 10.2.3 - Template Creation via CSRFEPSS 0.1%CVE-2026-1508MEDIUMCourt Reservation < 1.10.9 - Event Deletion via CSRFEPSS 0.1%CVE-2026-87973LOWIf-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion NameEPSS 0.1%CVE-2026-17520MEDIUMNewsletters < 4.17 - Unauthenticated API Access via Predictable API KeyEPSS 0.1%CVE-2026-87070MEDIUMForminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP SpoofingEPSS 0.1%