|
1771
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and includ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-2942
|
2026-04-25 03:05 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1772
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP Interface. Such manipulation of the argument jarFilePath leads to os command in…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5802
|
2026-04-25 03:05 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1773
|
8.1 |
HIGH
Network
|
-
|
-
|
The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field ke…
|
CWE-22
Path Traversal
|
CVE-2026-5436
|
2026-04-25 03:05 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1774
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions up to, and including, 4.14. This is due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5451
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1775
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5805
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1776
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5711
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1777
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cro…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5806
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1778
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5803
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1779
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/clie…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5808
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1780
|
3.5 |
LOW
Network
|
-
|
-
|
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5810
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|