Vulnerabilidades em devitemsllc
48 resultadosAnálise Vexday
A DevItems LLC apresenta 45 vulnerabilidades documentadas, com apenas 1 classificada como crítica e nenhuma sob exploração ativa conhecida no momento. O risco é moderado e estável, com a fraqueza dominante sendo injeção cross-site (CWE-79), embora apenas 2 vulnerabilidades tenham sido publicadas nos últimos 90 dias, sugerindo um ritmo controlado de descobertas.
CVE-2026-16811MEDIUMShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' ParameterEPSS 0.3%CVE-2024-5173MEDIUMHT Mega – Absolute Addons For Elementor <= 2.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Player Widget SettingsEPSS 0.3%CVE-2025-1527MEDIUMShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown ModuleEPSS 0.3%CVE-2026-16797MEDIUMShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' ParameterEPSS 0.2%CVE-2025-1261MEDIUMHT Mega – Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown WidgetEPSS 0.2%CVE-2025-13141MEDIUMHT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute InjectionEPSS 0.2%CVE-2025-11823MEDIUMShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via ShortcodeEPSS 0.2%CVE-2026-6287MEDIUMShopLentor - WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block AttributeEPSS 0.2%