|
2031
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.14.1 via a callback functio…
|
CWE-200
Information Exposure
|
CVE-2026-1307
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2032
|
6.5 |
MEDIUM
Network
|
-
|
-
|
El plugin Ninja Forms - The Contact Form Builder That Grows With You para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 3.14.1, inclusive, a través d…
|
CWE-200
Information Exposure
|
CVE-2026-1307
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2033
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability has been found in wandb OpenUI up to 0.0.0.0/1.0. This impacts an unknown function of the file backend/openui/config.py. The manipulation of the argument LITELLM_MASTER_KEY leads to h…
|
CWE-259 CWE-798
Use of Hard-coded Password Use of Hard-coded Credentials
|
CVE-2026-4993
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2034
|
3.3 |
LOW
Local
|
-
|
-
|
Se ha encontrado una vulnerabilidad en wandb OpenUI hasta 0.0.0.0/1.0. Esto afecta una función desconocida del archivo backend/openui/config.py. La manipulación del argumento LITELLM_MASTER_KEY condu…
|
CWE-259 CWE-798
Use of Hard-coded Password Use of Hard-coded Credentials
|
CVE-2026-4993
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2035
|
3.5 |
LOW
Adjacent
|
-
|
-
|
A vulnerability was found in wandb OpenUI up to 1.0/3.5-turb. Affected is the function generic_exception_handler of the file backend/openui/server.py of the component APIStatusError Handler. The mani…
|
CWE-200 CWE-209
Information Exposure Information Exposure Through an Error Message
|
CVE-2026-4994
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2036
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 2.…
|
CWE-93
CRLF Injection
|
CVE-2026-2442
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2037
|
5.3 |
MEDIUM
Network
|
-
|
-
|
El Page Builder: Pagelayer – plugin constructor de sitios web de arrastrar y soltar para WordPress es vulnerable a la Neutralización Incorrecta de Secuencias CRLF ('Inyección CRLF') en todas las vers…
|
CWE-93
CRLF Injection
|
CVE-2026-2442
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2038
|
3.5 |
LOW
Adjacent
|
-
|
-
|
Se encontró una vulnerabilidad en wandb OpenUI hasta 1.0/3.5-turb. Afecta a la función generic_exception_handler del archivo backend/openui/server.py del componente Gestor de APIStatusError. La manip…
|
CWE-200 CWE-209
Information Exposure Information Exposure Through an Error Message
|
CVE-2026-4994
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2039
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in wandb OpenUI up to 1.0. Affected by this vulnerability is an unknown functionality of the file frontend/public/annotator/index.html of the component Window Message E…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4995
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2040
|
3.5 |
LOW
Network
|
-
|
-
|
Se determinó una vulnerabilidad en wandb OpenUI hasta la versión 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo frontend/public/annotator/index.html del componente…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4995
|
2026-04-25 01:36 |
2026-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|