|
4361
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Neutralización incorrecta de elementos especiales utilizados en un comando SQL ('inyección SQL') vulnerabilidad en WPFactory Advanced WooCommerce Product Sales Reporting webd-woocommerce-advanced-rep…
|
CWE-89
SQL Injection
|
CVE-2026-24993
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4362
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.…
|
CWE-94
Code Injection
|
CVE-2026-25001
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4363
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de control inadecuado de la generación de código ('Inyección de Código') en Saad Iqbal Post Snippets post-snippets permite la Inclusión Remota de Código. Este problema afecta a Post Sn…
|
CWE-94
Code Injection
|
CVE-2026-25001
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4364
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThimPress LearnPress – Sepay Payment learnpress-sepay-payment allows Authentication Abuse.This issue affects LearnPress…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25002
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4365
|
7.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de omisión de autenticación usando una ruta o canal alternativo en ThimPress LearnPress – Sepay Payment learnpress-sepay-payment permite el abuso de autenticación. Este problema afecta…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-25002
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4366
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Bl…
|
CWE-89
SQL Injection
|
CVE-2026-25007
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4367
|
8.5 |
HIGH
Network
|
-
|
-
|
Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-ele…
|
CWE-89
SQL Injection
|
CVE-2026-25007
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4368
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Zone: from n/a thro…
|
CWE-862
Missing Authorization
|
CVE-2026-25009
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4369
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Vulnerabilidad de autorización faltante en raratheme Education Zone education-zone permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afec…
|
CWE-862
Missing Authorization
|
CVE-2026-25009
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4370
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WHMCSdes Phox Hosting phox-host allows Reflected XSS.This issue affects Phox Hosting: from n/a th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25013
|
2026-04-25 01:32 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|