|
2391
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin FormLift for Infusionsoft Web Forms para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 7.5.21, inclusive. Esto se debe a la falta de comprobaciones de c…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2392
|
7.2 |
HIGH
Network
|
-
|
-
|
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2393
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Blackhole for Bad Bots para WordPress es vulnerable a cross-site scripting almacenado a través del encabezado HTTP User-Agent en todas las versiones hasta la 3.8 inclusive. Esto se debe a u…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2394
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2395
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Blog2Social: Social Media Auto Post & Scheduler para WordPress es vulnerable a la pérdida de datos no autorizada en todas las versiones hasta la 8.8.2, inclusive. Esto se debe a que la …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2396
|
8.8 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Perf…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2397
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2398
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha identificado una debilidad en el sistema de pedidos de comida en línea code-projects 1.0. Esto afecta una parte desconocida del archivo form/cart.PHP del componente Módulo de Carrito de Compras…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2399
|
8.8 |
HIGH
Network
|
-
|
-
|
Se ha descubierto una vulnerabilidad de seguridad en Netcore Power 15AX hasta la versión 3.0.0.6938. Afectada por este problema es la función setTools del archivo /bin/netis.cgi del componente Diagno…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2400
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/grades/index.php?view=edit&id=1 of the component Para…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4842
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|