4.8

CVSS4.0

CVE-2026-5835 - code-projects Online Shoe Store admin_football.php cross site scripting

A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Executing a manipulation of the argument product_name can lead to cross site scripting. It is possible to launch the attack remotely. The e…

📅 Published: April 9, 2026, 2:45 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

4.8

CVSS4.0

CVE-2026-5834 - code-projects Online Shoe Store admin_running.php cross site scripting

A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now publi…

📅 Published: April 9, 2026, 2:30 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

4.3

CVSS3.1

CVE-2026-3568 - MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Us…

The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or valid…

📅 Published: April 9, 2026, 2:25 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

4.4

CVSS3.1

CVE-2026-3574 - Experto Dashboard for WooCommerce <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scrip…

The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings fields (including 'Navigation Font Size', 'Navigation Font Weight', 'Heading Font Size', 'Heading Font Weight', 'Text Font Size', and 'Text Font Weight') in all versions…

📅 Published: April 9, 2026, 2:25 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

6.4

CVSS3.1

CVE-2026-4429 - OSM <= 6.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker_name' Shortcod…

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'file_color_list' shortcode attribute of the [osm_map_v3] shortcode in all versions up to and including 6.1.15. This is due to insufficient input sanitization and output escaping. Thi…

📅 Published: April 9, 2026, 2:25 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

6.4

CVSS3.1

CVE-2026-5357 - Download Manager <= 3.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'wpdm_members' shortcode in versions up to and including 3.3.52. This is due to insufficient input sanitization and output escaping on the user-supplied 'sid' shortcode attribute. T…

📅 Published: April 9, 2026, 2:25 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

5.4

CVSS3.1

CVE-2026-4124 - Ziggeo <= 3.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via '…

The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The wp_ajax_ziggeo_ajax handler only verifies a nonce (check_ajax_referer) but performs no capability checks via current_user_can(). Furthermore, the nonce ('ziggeo_ajax_nonce') is e…

📅 Published: April 9, 2026, 2:25 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

4.8

CVSS4.0

CVE-2026-5833 - awwaiid mcp-server-taskwarrior index.ts server.setRequestHandler command injection

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. The attack must be carried out locally. The exploit has been di…

📅 Published: April 9, 2026, 2:15 a.m. 🔄 Last Modified: April 9, 2026, 12:59 p.m.

6.9

CVSS4.0

CVE-2026-5832 - atototo api-lab-mcp HTTP http-server.ts test_http_endpoint server-side request forgery

A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_test_scenarios/test_http_endpoint of the file src/mcp/http-server.ts of the component HTTP Interface. This manipulation of the argument source/url causes server-side request forger…

📅 Published: April 9, 2026, 2 a.m. 🔄 Last Modified: April 13, 2026, 3:02 p.m.

5.3

CVSS4.0

CVE-2026-5831 - Agions taskflow-ai terminal_execute handlers.ts os command injection

A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. Upgrading t…

📅 Published: April 9, 2026, 1:45 a.m. 🔄 Last Modified: April 9, 2026, 1:45 p.m.
Total resulsts: 344111
Page 69 of 34,412
« previous page » next page
Filters