|
3941
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting') vulnerabilidad en don-themes Molla molla permite XSS Reflejado. Este problema afecta a Molla: des…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32529
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3942
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation.This issue affects Creator LMS: from n/a through <= 1.1.18.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32530
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3943
|
8.8 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Asignación Incorrecta de Privilegios en WPFunnels Creator LMS creatorlms permite la escalada de privilegios. Este problema afecta a Creator LMS: desde n/a hasta <= 1.1.18.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-32530
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3944
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kunco kunco allows PHP Local File Inclusion.This issue affects Kunco: f…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32531
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3945
|
8.1 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de Control inadecuado del nombre de fichero para la declaración Include/Require en programa PHP ('inclusión remota de ficheros PHP') en gavias Kunco kunco permite la inclusión local de…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-32531
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3946
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Stored XSS.This iss…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32532
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3947
|
7.1 |
HIGH
Network
|
-
|
-
|
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder perm…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32532
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3948
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: f…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-32533
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3949
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en LatePoint LatePoint latepoint permite explotar niveles de seguridad de control de acceso configurados incorrec…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-32533
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3950
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk…
|
CWE-89
SQL Injection
|
CVE-2026-32534
|
2026-04-25 01:35 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|