Vulnerabilidades em smub

100 resultados
Análise Vexday

O portfólio de vulnerabilidades do vendor smub soma 91 CVEs catalogadas, com nenhuma entrada confirmada no catálogo CISA KEV — taxa que se situa abaixo da média geral do catálogo, indicando ausência de exploração ativa confirmada publicamente até o momento. Ainda assim, a CVE mais perigosa identificada, CVE-2024-3097, apresenta escore EPSS de 0,3802, sugerindo probabilidade não negligenciável de exploração futura e merecendo monitoramento prioritário. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), e a existência de ao menos uma PoC pública eleva o risco prático para equipes que ainda não aplicaram as correções correspondentes. O volume de 15 CVEs surgidas nos últimos 90 dias indica cadência de descoberta recente relevante, recomendando revisão contínua do ciclo de patching para produtos desse vendor.

CVE-2026-15452MEDIUMSmash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query StringEPSS 0.2%CVE-2025-10694MEDIUMUser Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information DisclosureEPSS 0.2%CVE-2026-7636MEDIUMSlider by Soliloquy <= 2.8.1 - Authenticated (Subscriber+) Information Disclosure via REST API EndpointEPSS 0.2%CVE-2026-84909MEDIUMCustom Twitter Feeds <= 2.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'buttoncolor' Shortcode AttributeEPSS 0.2%CVE-2025-12847MEDIUMAll in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media DeletionEPSS 0.2%CVE-2025-8149MEDIUMaThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown WidgetEPSS 0.2%CVE-2026-1236MEDIUMEnvira Gallery for WordPress <= 1.12.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST APIEPSS 0.2%CVE-2024-8200MEDIUMReviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request ForgeryEPSS 0.2%CVE-2025-12837MEDIUMaThemes Addons for Elementor <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action WidgetEPSS 0.2%CVE-2024-10045MEDIUMTransients Manager <= 2.0.6 - Cross-Site Request ForgeryEPSS 0.2%CVE-2025-4583MEDIUMSmash Balloon Instagram Feed <= 6.9.0 (Free) & <= 6.8.0 (Pro) - Authenticated (Contributor+) Stored Cross-Site Scripting via `data-plugin` AttributeEPSS 0.2%CVE-2025-1314MEDIUMCustom Twitter Feeds <= 2.2.5 - Cross-Site Request Forgery to Cache Reset via ctf_clear_cache_admin FunctionEPSS 0.2%CVE-2026-8613MEDIUMaThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget SettingEPSS 0.2%CVE-2025-11448MEDIUMGallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery ConversionEPSS 0.2%CVE-2025-5275MEDIUMCharitable <= 1.8.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Privacy SettingsEPSS 0.2%CVE-2026-16775MEDIUMSmash Balloon Social Post Feed <= 4.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode AttributeEPSS 0.2%CVE-2026-3177MEDIUMCharitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe WebhookEPSS 0.2%CVE-2025-8102MEDIUMEasy Digital Downloads <= 3.5.0 - Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install FunctionsEPSS 0.2%CVE-2026-12002MEDIUMSmash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' ParameterEPSS 0.1%CVE-2026-7533MEDIUMEasy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking via 'square_tokens' ParameterEPSS 0.1%