|
2741
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Jupiter X Core para WordPress es vulnerable a cargas de archivos limitadas debido a la falta de autorización en la función import_popup_templates() así como a una validación insuficiente de…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-3533
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2742
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Woocommerce Custom Product Addons Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.4.1 via the custom pricing formula eval() in the process_…
|
CWE-95
Eval Injection
|
CVE-2026-4001
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2743
|
9.8 |
CRITICAL
Network
|
-
|
-
|
El plugin Woocommerce Custom Product Addons Pro para WordPress es vulnerable a ejecución remota de código en todas las versiones hasta la 5.4.1, inclusive, a través de la fórmula de precios personali…
|
CWE-95
Eval Injection
|
CVE-2026-4001
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2744
|
8.1 |
HIGH
Network
|
-
|
-
|
The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmatio…
|
CWE-287
Improper Authentication
|
CVE-2026-4021
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2745
|
8.1 |
HIGH
Network
|
-
|
-
|
El plugin Contest Gallery para WordPress es vulnerable a una omisión de autenticación que conduce a la toma de control de la cuenta de administrador en todas las versiones hasta la 28.1.5, inclusive.…
|
CWE-287
Improper Authentication
|
CVE-2026-4021
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2746
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en SourceCodester Online Catering Reservation 1.0. Afectada es una función desconocida del archivo /search.php. Tal manipulación del argumento rcode conduce a inye…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4615
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2747
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /console/article/ of the component Article Title Handler. Performing a manipulati…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4616
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2748
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1.0. The impacted element is the function ValidateToken of the file /php/api_patient_checkin.php of the …
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-4617
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2749
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions…
|
CWE-862
Missing Authorization
|
CVE-2026-4056
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2750
|
5.4 |
MEDIUM
Network
|
-
|
-
|
El plugin User Registration & Membership para WordPress es vulnerable a la modificación no autorizada de datos debido a una comprobación de capacidad faltante en los endpoints de la API REST de R…
|
CWE-862
Missing Authorization
|
CVE-2026-4056
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|