|
4211
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in itsourcecode Online Enrollment System 1.0. This vulnerability affects unknown code of the file /sms/user/index.php?view=add of the component Parameter Handler. Execu…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4632
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4212
|
7.3 |
HIGH
Network
|
-
|
-
|
Una debilidad ha sido identificada en itsourcecode Online Enrollment System 1.0. Esta vulnerabilidad afecta código desconocido del archivo /sms/user/index.php?view=add del componente Gestor de Paráme…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4632
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4213
|
9.1 |
CRITICAL
Network
|
-
|
-
|
El plugin WP DSGVO Tools (GDPR) para WordPress es vulnerable a la destrucción no autorizada de cuentas en todas las versiones hasta la 3.1.38, inclusive. Esto se debe a que la acción AJAX 'super-unsu…
|
CWE-862
Missing Authorization
|
CVE-2026-4283
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4214
|
7.5 |
HIGH
Network
|
-
|
-
|
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter …
|
CWE-89
SQL Injection
|
CVE-2026-4662
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4215
|
7.5 |
HIGH
Network
|
-
|
-
|
El plugin JetEngine para WordPress es vulnerable a inyección SQL a través de la acción AJAX 'listing_load_more' en todas las versiones hasta la 3.8.6.1, inclusive. Esto se debe a que el parámetro 'fi…
|
CWE-89
SQL Injection
|
CVE-2026-4662
|
2026-04-25 01:32 |
2026-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4216
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/add-single-student-results.php of the component Parameter …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4783
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4217
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Una vulnerabilidad ha sido encontrada en itsourcecode College Management System 1.0. El elemento impactado es una función desconocida del archivo /admin/add-single-student-results.php del componente …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-4783
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4218
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Easy Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery shortcode post meta field in all versions up to, and including, 1.5.3. This is due to insuffic…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4766
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4219
|
6.4 |
MEDIUM
Network
|
-
|
-
|
El plugin Easy Image Gallery para WordPress es vulnerable a cross-site scripting almacenado a través del campo meta de la publicación del shortcode de Galería en todas las versiones hasta la 1.5.3, i…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4766
|
2026-04-25 01:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4220
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zorka allows Reflected XSS.This issue affects Zorka: from n/a through <= 1.5.7.
|
CWE-79
Cross-site Scripting
|
CVE-2025-69096
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|