|
2551
|
3.7 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protecte…
|
CWE-287
Improper Authentication
|
CVE-2026-4831
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2552
|
3.7 |
LOW
Network
|
-
|
-
|
Una falla de seguridad ha sido descubierta en kalcaddle kodbox 1.64. Afectada es la función can del archivo /workspace/source-code/app/controller/explorer/auth.class.php del componente Gestor de Comp…
|
CWE-287
Improper Authentication
|
CVE-2026-4831
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2553
|
3.3 |
LOW
Local
|
-
|
-
|
Se ha identificado una debilidad en Orc discount hasta 3.0.1.2. Este problema afecta a la función compile del archivo markdown.c del componente Markdown Gestor. Esta manipulación causa recursión inco…
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-4833
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2554
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en code-projects Accounting System 1.0. El elemento afectado es una función desconocida del archivo /my_account/delete.php. Realizar una manipulación del argumento co…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4836
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2555
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, an…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1986
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2556
|
6.1 |
MEDIUM
Network
|
-
|
-
|
El plugin FloristPress para Woo – Personaliza tu tienda de comercio electrónico para tu floristería para WordPress es vulnerable a cross-site scripting reflejado a través del parámetro 'noresults' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1986
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2557
|
7.2 |
HIGH
Network
|
-
|
-
|
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the 'post_content' of admin_form posts in all versions up to, and including, 3.28.31…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-3328
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2558
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Frontend Admin de DynamiApps para WordPress es vulnerable a Inyección de Objetos PHP a través de la deserialización del 'post_content' de publicaciones de tipo admin_form en todas las versi…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-3328
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2559
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4075
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2560
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin BWL Advanced FAQ Manager Lite para WordPress es vulnerable a cross-site scripting almacenado a través del shortcode 'baf_sbox' en todas las versiones hasta la 1.1.1 inclusive. Esto se debe …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4075
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|