|
3401
|
8.1 |
HIGH
Network
|
-
|
-
|
The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field ke…
|
CWE-22
Path Traversal
|
CVE-2026-5436
|
2026-04-25 03:05 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3402
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions up to, and including, 4.14. This is due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5451
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3403
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5805
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3404
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block attribute in the Posts Slider block in all versions up to, and including, 1.3.0 d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5711
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3405
|
3.5 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cro…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5806
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3406
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-5803
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3407
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an unknown function of the file apps/dashboard/src/app/(dashboard)/onboarding/clie…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5808
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3408
|
3.5 |
LOW
Network
|
-
|
-
|
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5810
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3409
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler.…
|
CWE-840
Business Logic Errors
|
CVE-2026-5811
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3410
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performin…
|
CWE-840
Business Logic Errors
|
CVE-2026-5812
|
2026-04-25 03:04 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|