|
3701
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter in versions up to, and including, 1.9.7 due to insufficient input sanitization…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2602
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3702
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Twentig para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'featuredImageSizeWidth' en versiones hasta la 1.9.7, inclusive, debido a una sanitización de e…
|
CWE-79
Cross-site Scripting
|
CVE-2026-2602
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3703
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the …
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5023
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3704
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Se ha encontrado una vulnerabilidad en DeDeveloper23 codebase-mcp hasta 3ec749d237dd8eabbeef48657cf917275792fde6. Esta vulnerabilidad afecta a la función getCodebase/getRemoteCodebase/saveCodebase de…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-5023
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3705
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_route=settings/users-view/ of the component Endpoint. The manipulation of the a…
|
CWE-99
Resource Injection
|
CVE-2026-5031
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3706
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Se encontró una vulnerabilidad en BichitroGan ISP Billing Software 2025.3.20. Afecta a una función desconocida del archivo /?_route=settings/users-view/ del componente Endpoint. La manipulación del a…
|
CWE-99
Resource Injection
|
CVE-2026-5031
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3707
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c of the component mxmlIndexNew. Executing a manipulation of the argument tempr c…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-5037
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3708
|
3.3 |
LOW
Local
|
-
|
-
|
Se determinó una vulnerabilidad en mxml hasta la versión 4.0.4. Este problema afecta a la función index_sort del archivo mxml-index.c del componente mxmlIndexNew. La ejecución de una manipulación del…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-5037
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3709
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the function fwrite of the file admin/pageMail.php. The manipulation of the argument …
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-5041
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3710
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en el Sistema de Gestión de Membresías de la Cámara de Comercio de code-projects 1.0. Afectada es la función fwrite del archivo admin/pageMail.PHP. La manipulación…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-5041
|
2026-04-25 01:36 |
2026-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|