|
1981
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name resul…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5834
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1982
|
2.4 |
LOW
Network
|
-
|
-
|
A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argumen…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5835
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1983
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler only verifies a nonce (check_ajax_referer) but per…
|
CWE-862
Missing Authorization
|
CVE-2026-4124
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1984
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5357
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1985
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Id…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-5833
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1986
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument prod…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5836
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1987
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The att…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5837
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1988
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints th…
|
CWE-862
Missing Authorization
|
CVE-2026-1830
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1989
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and im…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5742
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1990
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername ca…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5838
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|