|
3431
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_product.php. The manipulation of the argument prod…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-5836
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3432
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.php. The manipulation of the argument Comment results in sql injection. The att…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5837
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3433
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints th…
|
CWE-862
Missing Authorization
|
CVE-2026-1830
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3434
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. This is due to insufficient input sanitization of user-supplied URL fields and im…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5742
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3435
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the file /admin/add-subadmins.php. This manipulation of the argument sadminusername ca…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5838
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3436
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the file /admin/add-subcategory.php. Such manipulation of the argument sucatdescrip…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5839
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3437
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4336
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3438
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /admin/check_availability.php. Performing a manipulation of the argument Usernam…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-5840
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3439
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function of the file /api of the component Administrative API Endpoint. The manipulation…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-5842
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3440
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file /db/moviedb.sql of the component SQL Database Backup File Handler. Such manipul…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-5847
|
2026-04-25 03:03 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|