|
2661
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en WP Socio WP Telegram Widget and Join Link wptelegram-widget permite XSS Refl…
|
CWE-79
Cross-site Scripting
|
CVE-2026-23807
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2662
|
8.1 |
HIGH
Network
|
-
|
-
|
Deserialization of Untrusted Data vulnerability in xtemos WoodMart woodmart allows Object Injection.This issue affects WoodMart: from n/a through <= 8.3.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-23971
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2663
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de deserialización de datos no confiables en xtemos WoodMart woodmart permite la inyección de objetos. Este problema afecta a WoodMart: desde n/a hasta <= 8.3.8.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-23971
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2664
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.Thi…
|
CWE-862
Missing Authorization
|
CVE-2026-23972
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2665
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad por falta de autorización en magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce permite explotar niveles de seguridad de control de acceso configurado…
|
CWE-862
Missing Authorization
|
CVE-2026-23972
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2666
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5.
|
CWE-79
Cross-site Scripting
|
CVE-2026-23973
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2667
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en uxper Golo golo permite XSS Reflejado. Este problema afecta a Golo: desde n/a h…
|
CWE-79
Cross-site Scripting
|
CVE-2026-23973
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2668
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security …
|
CWE-862
Missing Authorization
|
CVE-2026-23977
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2669
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce permite la explotación de niveles de seguridad de control de …
|
CWE-862
Missing Authorization
|
CVE-2026-23977
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2670
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softwebmedia Gyan Elements gyan-elements allows Reflected XSS.This issue affects Gyan Elements: f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-23979
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|