|
2591
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Easy Image Gallery para WordPress es vulnerable a cross-site scripting almacenado a través del campo meta de la publicación del shortcode de Galería en todas las versiones hasta la 1.5.3, i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4766
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2592
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zorka allows Reflected XSS.This issue affects Zorka: from n/a through <= 1.5.7.
|
CWE-79
Cross-site Scripting
|
CVE-2025-69096
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2593
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en G5Theme Zorka zorka permite XSS Reflejado. Este problema afecta a Zorka: desde …
|
CWE-79
Cross-site Scripting
|
CVE-2025-69096
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2594
|
8.5 |
HIGH
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-69347
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2595
|
8.5 |
HIGH
Network
|
-
|
-
|
Elusión de autorización a través de vulnerabilidad de clave controlada por el usuario en la suscripción de Convers Lab WPSubscription permite explotar niveles de seguridad de control de acceso config…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-69347
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2596
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime:…
|
CWE-862
Missing Authorization
|
CVE-2025-69358
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2597
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en Metagauss EventPrime eventprime-event-calendar-management permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. …
|
CWE-862
Missing Authorization
|
CVE-2025-69358
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2598
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in flexcubed PitchPrint pitchprint allows Path Traversal.This issue affects PitchPrint: from n/a through <…
|
CWE-22
Path Traversal
|
CVE-2026-22448
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2599
|
7.5 |
HIGH
Network
|
-
|
-
|
Limitación incorrecta de un nombre de ruta a un directorio restringido ('Salto de ruta') vulnerabilidad en flexcubed PitchPrint pitchprint permite Salto de ruta. Este problema afecta a PitchPrint: de…
|
CWE-22
Path Traversal
|
CVE-2026-22448
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2600
|
7.2 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Object Injection.This issue affects Product Feed for WooCommerce: from n/a thro…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-22480
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|