|
2021
|
8.0 |
HIGH
Network
|
-
|
-
|
The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag…
|
CWE-285
Improper Authorization
|
CVE-2026-4248
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2022
|
8.0 |
HIGH
Network
|
-
|
-
|
El plugin Ultimate Member para WordPress es vulnerable a la exposición de información sensible en todas las versiones hasta e incluyendo la 2.11.2. Esto se debe a que la etiqueta de plantilla '{userm…
|
CWE-285
Improper Authorization
|
CVE-2026-4248
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2023
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Perfo…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4991
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2024
|
3.5 |
LOW
Network
|
-
|
-
|
Una vulnerabilidad fue detectada en QDOCS Smart School Management System hasta la versión 7.2. El elemento afectado es una función desconocida del archivo /admin/enquiry del componente Módulo de Cons…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4991
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2025
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/openui/server.py of the component HTMLAnnotator Component. Executing a manipulati…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4992
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2026
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha encontrado una vulnerabilidad en wandb OpenUI hasta la versión 1.0. Esto afecta a la función create_share/get_share del archivo backend/openui/server.py del componente HTMLAnnotator Component. …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4992
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2027
|
7.5 |
HIGH
Network
|
-
|
-
|
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount Bypass in all versions up to, and including, 2.5.2. This is due to the crea…
|
CWE-20
Improper Input Validation
|
CVE-2026-4987
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2028
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin SureForms – Contact Form, Payment Form & Other Custom Form Builder para WordPress es vulnerable a la Omisión de Cantidad de Pago en todas las versiones hasta la 2.5.2, inclusive. Esto s…
|
CWE-20
Improper Input Validation
|
CVE-2026-4987
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2029
|
7.2 |
HIGH
Network
|
-
|
-
|
The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8 via the laborator_calc_route AJAX action. This makes it possible for unau…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-12886
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2030
|
7.2 |
HIGH
Network
|
-
|
-
|
El tema Oxygen Theme para WordPress es vulnerable a falsificación de petición del lado del servidor en todas las versiones hasta la 6.0.8, inclusive, a través de la acción AJAX laborator_calc_route. …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-12886
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|