|
2921
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin de shortcodes fyyd podcast para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los shortcodes 'fyyd-podcast', 'fyyd-episode' y 'fyyd' en todas las versiones hasta la …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4084
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2922
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Random Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cat', 'nocat', and 'text' shortcode attributes of the 'wp_random_button' shortcode in all versions up t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4086
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2923
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin WP Random Button para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los atributos del shortcode 'cat', 'nocat' y 'text' del shortcode 'wp_random_button' en todas las…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4086
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2924
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.5.9. The `speedup01_ajax_enabled()` function, which handles the `wp_ajax_spe…
|
CWE-862
Missing Authorization
|
CVE-2026-4127
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2925
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Speedup Optimization para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 1.5.9 inclusive. La función speedup01_ajax_enabled(), que maneja la acción AJAX …
|
CWE-862
Missing Authorization
|
CVE-2026-4127
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2926
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-4511
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2927
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en vanna-ai vanna hasta la versión 2.0.2. Afectada es la función exec del archivo /src/vanna/legacy. Dicha manipulación conduce a inyección. El ataqu…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-4511
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2928
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injectio…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4513
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2929
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en vanna-ai vanna hasta 2.0.2. Afectada por esta vulnerabilidad es la función ask del archivo vanna\legacy\base\base.py. Realizar una manipulación resulta en inyecció…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4513
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2930
|
7.5 |
HIGH
Network
|
-
|
-
|
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' metho…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-4373
|
2026-04-25 01:27 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|