Busca de CVEs
398.697 resultadosCVE-2026-95866HIGHUser Profile Builder <= 4.0.2 - Unauthenticated Stored Cross-Site Scripting via Avatar FieldEPSS 0.3%CVE-2026-96568HIGHRestaurant Menu and Food Ordering <= 2.4.14 - Unauthenticated Stored Cross-Site Scripting via 'phone_number' ParameterEPSS 0.2%CVE-2026-93656MEDIUMUser Profile Builder <= 4.0.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar FieldEPSS 0.2%CVE-2026-13456HIGHWP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' ParameterEPSS 0.7%CVE-2026-93654HIGHPremium Packages <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' ParameterEPSS 0.2%CVE-2026-17577MEDIUMSSL Zen <= 4.7.42 - Reflected Cross-Site Scripting via 'uri' ParameterEPSS 0.3%CVE-2026-92713HIGHModula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' ParameterEPSS 0.3%CVE-2026-93747MEDIUMwpForo Forum <= 3.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'telegram' Profile FieldEPSS 0.2%CVE-2026-88996MEDIUMWPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST ParameterEPSS 0.3%CVE-2026-96752HIGHZero Spam for WordPress <= 5.7.10 - Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 IntegrationEPSS 0.2%CVE-2026-96448MEDIUMKeycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalationEPSS 0.2%CVE-2026-93477MEDIUMPrivate action arguments can be set by user input on the bulk destroy and bulk update paths in AshEPSS 0.2%CVE-2026-94376MEDIUMBetter Messages <= 3.0.4 - Authenticated (Subscriber+) Stored DOM-Based Cross-Site Scripting via User Display NameEPSS 0.2%CVE-2026-14281CRITICALAutomation Web Platform <= 4.8.6 - Unauthenticated Privilege Escalation via 'wawp_custom_fields' ParameterEPSS 0.5%CVE-2026-92746MEDIUMGutenverse <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comment Block 'suffixMain' AttributeEPSS 0.2%CVE-2026-96039HIGHBA Book Everything <= 1.8.27 - Unauthenticated Stored Cross-Site Scripting via first_name ParameterEPSS 0.2%CVE-2026-93303HIGHHT Contact Form <= 2.10.1 - Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/ResumeEPSS 0.2%CVE-2026-93399CRITICALOnline Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' ParameterEPSS 0.4%CVE-2026-92799MEDIUMOnline Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_dataEPSS 0.3%CVE-2026-92829MEDIUMBlog2Social: Social Media Auto Post & Scheduler <= 9.1.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via Multiple AJAX HandlersEPSS 0.3%