|
3601
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Gaea gaea allows Reflected XSS.This issue affects Gaea: from n/a through < 3.8.
|
CWE-79
Cross-site Scripting
|
CVE-2026-32518
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3602
|
7.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') en imithemes Gaea gaea permite XSS Reflejado. Este problema afecta a Gaea: desd…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32518
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3603
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through <= 1.2.2.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32519
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3604
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Bit Apps Bit SMTP bit-smtp permite la escalada de privilegios. Este problema afecta a Bit SMTP: desde n/a hasta <= 1.2.2.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32519
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3605
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32520
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3606
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en Andrew Munro / AffiliateWP RewardsWP rewardswp permite la escalada de privilegios. Este problema afecta a RewardsWP: desde n/d hasta <= 1.…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32520
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3607
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface allows DOM-Based XS…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32521
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3608
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Northern Beaches Websites WP Custom Admin Interface wp-custom-admin-interface p…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32521
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3609
|
8.6 |
HIGH
Network
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This…
|
CWE-22
Path Traversal
|
CVE-2026-32522
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3610
|
8.6 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Limitación Incorrecta de un Nombre de Ruta a un Directorio Restringido ('Salto de Ruta') en vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system permite Salt…
|
CWE-22
Path Traversal
|
CVE-2026-32522
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|