|
2611
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2612
|
4.9 |
MEDIUM
Network
|
-
|
-
|
El plugin Complianz – GDPR/CCPA Cookie Consent para WordPress es vulnerable a Cross-Site Scripting Almacenado en todas las versiones hasta la 7.4.4.2, inclusive. Esto se debe a que la función 'revert…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2613
|
7.5 |
HIGH
Network
|
-
|
-
|
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, an…
|
CWE-89
SQL Injection
|
CVE-2026-2511
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2614
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin JS Help Desk – AI-Powered Support & Ticketing System para WordPress es vulnerable a inyección SQL a través del parámetro 'multiformid' en la función 'storeTickets()' en todas las versio…
|
CWE-89
SQL Injection
|
CVE-2026-2511
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2615
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file /dbfood/contact.php. The manipulation of the ar…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4898
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2616
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en code-projects Online Food Ordering System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /dbfood/contact.php. La manipulació…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4898
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2617
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4899
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2618
|
2.4 |
LOW
Network
|
-
|
-
|
Se ha descubierto una falla de seguridad en el sistema de pedidos de comida en línea 1.0 de code-projects. Afectada por este problema está alguna funcionalidad desconocida del archivo /dbfood/food.PH…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4899
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2619
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessib…
|
CWE-425 CWE-552
Direct Request ('Forced Browsing') Files or Directories Accessible to External Parties
|
CVE-2026-4900
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2620
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en el Sistema de Pedidos de Comida en Línea 1.0 de code-projects. Esto afecta una parte desconocida del archivo /dbfood/localhost.sql. Esta manipulación provoca que l…
|
CWE-425 CWE-552
Direct Request ('Forced Browsing') Files or Directories Accessible to External Parties
|
CVE-2026-4900
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|