|
2571
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the conne…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2572
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all vers…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2573
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El fragmento DSGVO para Leaflet Map y su plugin Extensions para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los shortcodes 'leafext-cookie-time' y 'leafext-delete-cookie' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2574
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El plugin FormLift for Infusionsoft Web Forms para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 7.5.21, inclusive. Esto se debe a la falta de comprobaciones de c…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2575
|
7.2 |
HIGH
Network
|
-
|
-
|
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2576
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Blackhole for Bad Bots para WordPress es vulnerable a cross-site scripting almacenado a través del encabezado HTTP User-Agent en todas las versiones hasta la 3.8 inclusive. Esto se debe a u…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4329
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2577
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2578
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Blog2Social: Social Media Auto Post & Scheduler para WordPress es vulnerable a la pérdida de datos no autorizada en todas las versiones hasta la 8.8.2, inclusive. Esto se debe a que la …
|
CWE-862
Missing Authorization
|
CVE-2026-4331
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2579
|
8.8 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTools of the file /bin/netis.cgi of the component Diagnostic Tool Interface. Perf…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-4840
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2580
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file form/cart.php of the component Shopping Cart Module. Executing a manipulation…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4841
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|