Vulnerabilidades em dokaninc
6 resultadosAnálise Vexday
A Dokan Inc apresenta 6 vulnerabilidades catalogadas, com 4 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta. Nenhuma está sob exploração ativa confirmada (KEV) e não há críticas por CVSS, reduzindo o risco imediato. A fraqueza dominante é CWE-639 (autorização inadequada), sugerindo exposição a controles de acesso que requerem atenção em ambientes sensíveis.
CVE-2020-36748MEDIUMDokan <= 3.0.8 - Cross-Site Request Forgery BypassEPSS 0.5%CVE-2026-11987MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' ParameterEPSS 0.3%CVE-2025-14977HIGHDokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information DisclosureEPSS 0.3%CVE-2026-3504MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 4.3.1 - Unauthenticated Information Disclosure in Store Reviews REST API EndpointEPSS 0.3%CVE-2026-10023MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX HandlersEPSS 0.2%CVE-2026-11783MEDIUMDokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.4 - Authenticated (Custom+) Stored Cross-Site Scripting via Product SKUEPSS 0.2%