|
2561
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post_title in all versions up to, and including, 6.4.3. This is due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4335
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2562
|
5.4 |
MEDIUM
Network
|
-
|
-
|
El plugin ShortPixel Image Optimizer para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del post_title del adjunto en todas las versiones hasta la 6.4.3, inclusive. Esto se debe …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4335
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2563
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the file /display.php. Executing a manipulation of the argument ID can lead to sql inj…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2564
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una falla en SourceCodester Malawi Online Market 1.0. El elemento afectado es una función desconocida del archivo /display.PHP. La ejecución de una manipulación del argumento ID pued…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2565
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argum…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2566
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en SourceCodester Food Ordering System 1.0. Esto afecta una función desconocida del archivo /purchase.PHP del componente Gestor de Parámetros. La manipulación de…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2567
|
8.8 |
HIGH
Network
|
-
|
-
|
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objec…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2568
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Amelia Booking para WordPress es vulnerable a Referencias Directas Inseguras a Objetos en versiones hasta la 9.1.2, inclusive. Esto se debe a que el plugin proporciona acceso controlado por…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2569
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2570
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Simple Download Counter para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del shortcode 'sdc_menu' en todas las versiones hasta la 2.3, inclusive. Esto se debe a una s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|