Vulnerabilidades em Unknown

5.635 resultados
Análise Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-14566MEDIUMAdvanced Customized Prompts <= 1.0.1 - Subscriber+ WooCommerce Order Item Metadata TamperingEPSS 0.1%CVE-2026-16569MEDIUMShopApper <= 0.4.62 - Subscriber+ Arbitrary Product Stock UpdateEPSS 0.1%CVE-2025-7965MEDIUMCBX Restaurant Booking <= 1.2.1 - Plugin Reset via CSRFEPSS 0.1%CVE-2025-9116MEDIUMWPS Visitor Counter Plugin <= 1.4.8 - Reflected XSS via $_SERVER['REQUEST_URI']EPSS 0.1%CVE-2026-12724MEDIUMKirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-passwordEPSS 0.1%CVE-2026-97318MEDIUMGiveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' ParameterEPSS 0.1%CVE-2026-89050MEDIUMQuads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URLEPSS 0.1%CVE-2026-87971HIGHIf-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' ParameterEPSS 0.1%CVE-2026-79621MEDIUMCatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared TransientEPSS 0.1%CVE-2026-2466HIGHDukaPress <= 3.2.4 - Reflected XSSEPSS 0.1%CVE-2026-103378MEDIUMGeliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Public Log FileEPSS 0.1%CVE-2026-14239HIGHTourmaster < 5.4.8 - Stored XSS via CSRFEPSS 0.1%CVE-2026-14234HIGHWOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRFEPSS 0.1%CVE-2025-15611MEDIUMPopup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRFEPSS 0.1%CVE-2026-19088MEDIUMShopEngine < 4.9.3 - Customer PII Disclosure via Forced AuthenticationEPSS 0.1%CVE-2025-11154MEDIUMIDonate < 2.1.13 - Unauthenticated User DeletionEPSS 0.1%CVE-2026-13729MEDIUMPodlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRFEPSS 0.1%CVE-2026-85641MEDIUMFormidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' ParameterEPSS 0.1%CVE-2026-13414MEDIUMCMP - Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajaxEPSS 0.1%CVE-2026-82127LOWSchema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term FieldsEPSS 0.1%