|
2601
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /admin/mod_amenities/index.php?view=add. This manipulation of…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4875
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2602
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Se determinó una vulnerabilidad en itsourcecode Free Hotel Reservation System 1.0. El elemento afectado es una función desconocida del archivo /admin/mod_amenities/index.PHP?view=add. Esta manipulaci…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4875
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2603
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.6. This is due to missing nonce validation on the 'save_options' funct…
|
CWE-352
Origin Validation Error
|
CVE-2026-1032
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2604
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Conditional Menus para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.2.6, inclusive. Esto se debe a la falta de validación de n…
|
CWE-352
Origin Validation Error
|
CVE-2026-1032
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2605
|
7.2 |
HIGH
Network
|
-
|
-
|
The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2231
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2606
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Fluent Booking para WordPress es vulnerable a cross-site scripting almacenado a través de múltiples parámetros en todas las versiones hasta la 2.0.01, inclusive, debido a una sanitización d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2231
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2607
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulatio…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4876
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2608
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en itsourcecode Free Hotel Reservation System 1.0. El elemento impactado es una función desconocida del archivo /admin/mod_amenities/index.php?view=editpic. Tal ma…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4876
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2609
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page result…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4877
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2610
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha descubierto una falla de seguridad en el Sistema de Gestión de Nóminas itsourcecode hasta la versión 1.0. Esto afecta a una función desconocida del archivo /index.PHP. Realizar una manipulación…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4877
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|