|
2381
|
7.3 |
HIGH
Network
|
-
|
-
|
Se ha encontrado una falla en SourceCodester Malawi Online Market 1.0. El elemento afectado es una función desconocida del archivo /display.PHP. La ejecución de una manipulación del argumento ID pued…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4838
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2382
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file /purchase.php of the component Parameter Handler. The manipulation of the argum…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2383
|
7.3 |
HIGH
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en SourceCodester Food Ordering System 1.0. Esto afecta una función desconocida del archivo /purchase.PHP del componente Gestor de Parámetros. La manipulación de…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4839
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2384
|
8.8 |
HIGH
Network
|
-
|
-
|
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objec…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2385
|
8.8 |
HIGH
Network
|
-
|
-
|
El plugin Amelia Booking para WordPress es vulnerable a Referencias Directas Inseguras a Objetos en versiones hasta la 9.1.2, inclusive. Esto se debe a que el plugin proporciona acceso controlado por…
|
CWE-269
Improper Privilege Management
|
CVE-2026-2931
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2386
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2387
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Simple Download Counter para WordPress es vulnerable a Cross-Site Scripting Almacenado a través del shortcode 'sdc_menu' en todas las versiones hasta la 2.3, inclusive. Esto se debe a una s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4278
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2388
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 7.5.21. This is due to missing capability checks on the conne…
|
CWE-862
Missing Authorization
|
CVE-2026-4281
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2389
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `leafext-cookie-time` and `leafext-delete-cookie` shortcodes in all vers…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2390
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El fragmento DSGVO para Leaflet Map y su plugin Extensions para WordPress es vulnerable a Cross-Site Scripting Almacenado a través de los shortcodes 'leafext-cookie-time' y 'leafext-delete-cookie' en…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|