|
1801
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5357
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1802
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Id…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-5833
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1803
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument prod…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5836
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1804
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The att…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5837
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1805
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints th…
|
CWE-862
Missing Authorization
|
CVE-2026-1830
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1806
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and im…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5742
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1807
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername ca…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5838
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1808
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the file /admin/add-subcategory.php. Such manipulation of the argument sucatdescrip…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5839
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1809
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4336
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1810
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /admin/check_availability.php. Performing a manipulation of the argument Usernam…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5840
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|