5.4

CVSS3.1

CVE-2026-42641 - WordPress Share This Image plugin <= 2.14 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

4.3

CVSS3.1

CVE-2026-42645 - WordPress Barcode Scanner with Inventory & Order Manager plugin <= 1.11.0 - Cross Site Request Forgโ€ฆ

Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: fโ€ฆ

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

4.3

CVSS3.1

CVE-2026-42648 - WordPress Spectra plugin <= 2.19.22 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through <= 2.19.22.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

5.3

CVSS3.1

CVE-2026-42642 - WordPress GiveWP plugin <= 4.14.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

7.6

CVSS3.1

CVE-2026-42646 - WordPress TaxoPress plugin <= 3.44.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPress simple-tags allows Blind SQL Injection.This issue affects TaxoPress: from n/a through <= 3.44.0.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

5.9

CVSS3.1

CVE-2026-42643 - WordPress Image Widget plugin <= 4.4.11 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Widget image-widget allows Stored XSS.This issue affects Image Widget: from n/a through <= 4.4.11.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

5.3

CVSS3.1

CVE-2026-42644 - WordPress BetterDocs plugin <= 4.3.10 - Sensitive Data Exposure vulnerability

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs betterdocs allows Retrieve Embedded Sensitive Data.This issue affects BetterDocs: from n/a through <= 4.3.10.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

7.1

CVSS3.1

CVE-2026-42652 - WordPress User Registration plugin <= 5.1.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through <= 5.1.5.

๐Ÿ“… Published: April 29, 2026, 10:40 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 10:47 a.m.

8.7

CVSS4.0

CVE-2026-42518 - Information Disclosure Vulnerability in e-Sushrut HMIS

This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in client-side JavaScript. An unauthenticated remote attacker could exploit this vulnerability by accessing the client-side code to extract sensitive information and cryptographic keyโ€ฆ

๐Ÿ“… Published: April 29, 2026, 8:37 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 8:37 a.m.

10

CVSS4.0

CVE-2026-3325 - SQL injection in MegaCMS by CRM Sistemas de Fidelizaciรณn

SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the โ€œid_territorioโ€ parameter of the โ€œ/web_comunications/cms/get_provinciasโ€ endpoint. The vulnerability arises from inadequate validation and sanitisation of user input. Specifically, via a POST request, the โ€œid_territorioโ€ parameter, used iโ€ฆ

๐Ÿ“… Published: April 29, 2026, 8:37 a.m. ๐Ÿ”„ Last Modified: April 29, 2026, 8:37 a.m.
Total resulsts: 347752
Page 65 of 34,776
ยซ previous page ยป next page
Filters