Vulnerabilidades em Unknown

5.635 resultados
Análise Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-86809MEDIUMPersian Elementor < 2.8.2 - Unauthenticated ZarinPal Payment Callback Authority BypassEPSS 0.2%CVE-2026-14936MEDIUMSimple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver VerificationEPSS 0.2%CVE-2026-84044MEDIUMRestaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPNEPSS 0.2%CVE-2026-15208MEDIUMRegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal VerificationEPSS 0.2%CVE-2026-92400MEDIUMPayment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Sandbox IPN Environment ConfusionEPSS 0.2%CVE-2026-16650MEDIUMCharitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature BypassEPSS 0.2%CVE-2026-83533MEDIUMWP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_paymentEPSS 0.2%CVE-2026-15150MEDIUMmyCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCREDEPSS 0.2%CVE-2026-84043MEDIUMePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation BypassEPSS 0.2%CVE-2026-12501MEDIUMWP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount VerificationEPSS 0.2%CVE-2026-82184MEDIUMWPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option UpdateEPSS 0.2%CVE-2026-86833MEDIUMMetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field ShortcodesEPSS 0.2%CVE-2026-1369MEDIUMConditional CAPTCHA <= 4.0.0 - Open RedirectEPSS 0.2%CVE-2024-8085MEDIUMPeoplePond <= 1.1.9 - CSRF to Stored XSSEPSS 0.2%CVE-2026-82849MEDIUMMasteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOREPSS 0.2%CVE-2024-8095MEDIUMBabelZ – Google Translate Widget <= 1.1.5 - CSRF to Stored XSSEPSS 0.2%CVE-2026-78397MEDIUMLink Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link ValidationEPSS 0.2%CVE-2024-8032MEDIUMSmooth Gallery Replacement <= 1.0 - CSRF to Stored XSSEPSS 0.2%CVE-2026-89190MEDIUMRobin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajaxEPSS 0.2%CVE-2025-2247MEDIUMWP-PManager <= 1.2 - Category Deletion via CSRFEPSS 0.2%