|
2421
|
4.3 |
MEDIUM
Network
|
-
|
-
|
El plugin Conditional Menus para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta la 1.2.6, inclusive. Esto se debe a la falta de validación de n…
|
CWE-352
Origin Validation Error
|
CVE-2026-1032
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2422
|
7.2 |
HIGH
Network
|
-
|
-
|
The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and ou…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2231
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2423
|
7.2 |
HIGH
Network
|
-
|
-
|
El plugin Fluent Booking para WordPress es vulnerable a cross-site scripting almacenado a través de múltiples parámetros en todas las versiones hasta la 2.0.01, inclusive, debido a una sanitización d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2231
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2424
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulatio…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4876
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2425
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en itsourcecode Free Hotel Reservation System 1.0. El elemento impactado es una función desconocida del archivo /admin/mod_amenities/index.php?view=editpic. Tal ma…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4876
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2426
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page result…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4877
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2427
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se ha descubierto una falla de seguridad en el Sistema de Gestión de Nóminas itsourcecode hasta la versión 1.0. Esto afecta a una función desconocida del archivo /index.PHP. Realizar una manipulación…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4877
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2428
|
4.9 |
MEDIUM
Network
|
-
|
-
|
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2429
|
4.9 |
MEDIUM
Network
|
-
|
-
|
El plugin Complianz – GDPR/CCPA Cookie Consent para WordPress es vulnerable a Cross-Site Scripting Almacenado en todas las versiones hasta la 7.4.4.2, inclusive. Esto se debe a que la función 'revert…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2389
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2430
|
7.5 |
HIGH
Network
|
-
|
-
|
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, an…
|
CWE-89
SQL Injection
|
CVE-2026-2511
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|