|
4061
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en code-projects Online Food Ordering System 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /dbfood/contact.php. La manipulació…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4898
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4062
|
2.4 |
LOW
Network
|
-
|
-
|
A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /dbfood/food.php. The manipulation of the argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4899
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4063
|
2.4 |
LOW
Network
|
-
|
-
|
Se ha descubierto una falla de seguridad en el sistema de pedidos de comida en línea 1.0 de code-projects. Afectada por este problema está alguna funcionalidad desconocida del archivo /dbfood/food.PH…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4899
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4064
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessib…
|
CWE-425 CWE-552
Direct Request ('Forced Browsing') Files or Directories Accessible to External Parties
|
CVE-2026-4900
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4065
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Se ha identificado una debilidad en el Sistema de Pedidos de Comida en Línea 1.0 de code-projects. Esto afecta una parte desconocida del archivo /dbfood/localhost.sql. Esta manipulación provoca que l…
|
CWE-425 CWE-552
Direct Request ('Forced Browsing') Files or Directories Accessible to External Parties
|
CVE-2026-4900
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4066
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s7.php. This manipulation of the argument sname causes cross site …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4909
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4067
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component En…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4907
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4068
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad fue identificada en Page-Replica Page Replica hasta e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. El elemento impactado es la función sitemap.fetch del archivo /sitemap del componente …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4907
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4069
|
2.4 |
LOW
Network
|
-
|
-
|
Se ha identificado una debilidad en code-projects Exam Form Submission 1.0/7.PHP. Esto afecta una función desconocida del archivo /admin/update_s7.PHP. Esta manipulación del argumento sname causa cro…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-4909
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4070
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticate…
|
CWE-862
Missing Authorization
|
CVE-2026-3098
|
2026-04-25 01:35 |
2026-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|