Vulnerabilidades en Unknown

5615 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-15046MEDIUMLitExtension: Store to WooCommerce Migration <= 1.2.5 - Connector Token Takeover via CSRFEPSS 0.1%CVE-2026-88848MEDIUMMasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction BypassEPSS 0.1%CVE-2025-10684MEDIUMConstruction Light < 1.6.8 - Subscriber+ Arbitrary Plugin ActivationEPSS 0.1%CVE-2026-87978MEDIUMPaymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscription Transaction CallbackEPSS 0.1%CVE-2026-89411MEDIUMPaymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntentEPSS 0.1%CVE-2026-92996MEDIUMVerge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_doneEPSS 0.1%CVE-2026-1128MEDIUMWP eCommerce <= 3.15.1 - Coupon Deletion via CSRFEPSS 0.1%CVE-2026-13159MEDIUMReal Estate Papi <= 1.0.5 - Subscriber+ Plugin InstallationEPSS 0.1%CVE-2026-81338MEDIUMMasterStudy LMS < 3.7.50 - Subscriber+ Stored HTML Injection via Course DiscussionsEPSS 0.1%CVE-2026-17522MEDIUMNewsletters < 4.17 - Arbitrary Plugin Option Update via CSRFEPSS 0.1%CVE-2026-91832HIGHWP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRFEPSS 0.1%CVE-2026-104652MEDIUMEnvira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image IDEPSS —CVE-2026-104953MEDIUMMPG < 4.2.3 - Editor+ SQLi via Project ImportEPSS —CVE-2026-82212HIGHNexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification HandlerEPSS —CVE-2026-86833MEDIUMMetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field ShortcodesEPSS —CVE-2026-97354MEDIUMPowerPress 11.13.12 - 11.17.9 - Contributor+ SSRF via Media URL RedirectsEPSS —CVE-2026-87971HIGHIf-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' ParameterEPSS —CVE-2026-103681MEDIUMFrontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_profile_deleteEPSS —CVE-2026-86816MEDIUMWPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST APIEPSS —CVE-2026-105322MEDIUMMagee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact FormEPSS —