Vulnerabilidades em smub

100 resultados
Análise Vexday

O portfólio de vulnerabilidades do vendor smub soma 91 CVEs catalogadas, com nenhuma entrada confirmada no catálogo CISA KEV — taxa que se situa abaixo da média geral do catálogo, indicando ausência de exploração ativa confirmada publicamente até o momento. Ainda assim, a CVE mais perigosa identificada, CVE-2024-3097, apresenta escore EPSS de 0,3802, sugerindo probabilidade não negligenciável de exploração futura e merecendo monitoramento prioritário. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), e a existência de ao menos uma PoC pública eleva o risco prático para equipes que ainda não aplicaram as correções correspondentes. O volume de 15 CVEs surgidas nos últimos 90 dias indica cadência de descoberta recente relevante, recomendando revisão contínua do ciclo de patching para produtos desse vendor.

CVE-2025-4577MEDIUMSmash Balloon Custom Facebook Feed <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-color` AttributeEPSS 0.3%CVE-2025-12377MEDIUMGallery Plugin for WordPress – Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery ActionsEPSS 0.3%CVE-2025-11271MEDIUMEasy Digital Download <= 3.5.2 - Insufficient Verification to Order ManipulationEPSS 0.3%CVE-2026-7792MEDIUMWPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook EndpointEPSS 0.3%CVE-2026-5488MEDIUMExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'EPSS 0.3%CVE-2026-15782MEDIUMWPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post ContentEPSS 0.3%CVE-2026-77189MEDIUMCharitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode AttributeEPSS 0.3%CVE-2025-3794MEDIUMWPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' ParameterEPSS 0.3%CVE-2026-5075MEDIUMAll in One SEO <= 4.9.7 - Authenticated (Contributor+) Sensitive Information Exposure via 'internalOptions' Localized Script DataEPSS 0.3%CVE-2026-10038MEDIUMCharitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' ParameterEPSS 0.3%CVE-2024-10593MEDIUMWPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log DeletionEPSS 0.3%CVE-2026-7619MEDIUMCharitable <= 1.8.10.4 - Authenticated (Custom+) SQL Injection via 's' Search ParameterEPSS 0.3%CVE-2024-4473MEDIUMSydney Toolbox <= 1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio WidgetEPSS 0.3%CVE-2025-2892MEDIUMAll in One SEO Pack <= 4.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Description and Canonical URLEPSS 0.3%CVE-2026-6566MEDIUMPhoto Gallery, Sliders, Proofing and Themes <= 4.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Image Deletion via REST APIEPSS 0.3%CVE-2025-2537MEDIUMMultiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via ThickBox JavaScript LibraryEPSS 0.3%CVE-2025-14384MEDIUMAll in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit DisclosureEPSS 0.2%CVE-2024-13547MEDIUMaThemes Addons for Elementor <= 1.0.12 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2026-3423MEDIUMEnvira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery DescriptionEPSS 0.2%CVE-2024-13517MEDIUMEasy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via TitleEPSS 0.2%