69 Failles indexées
17 Critiques
14 Élevées
2 Ajoutées aujourd'hui

14 failles trouvées

filtres actifs
CVE-2026-6108
Modérée 6.3

A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Model Context Protocol Node. Performing a manipulation results in os command injection. The attack is po

CVE-2026-5207
Modérée 6.5

The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 9.2.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen

CVE-2026-5226
Modérée 6.1

The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths in the get_current_url() function, which are inserted into Jav

CVE-2026-4895
Modérée 6.4

The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.8.9 This is due to insufficient input sanitization and output escaping in the gspb_greenShift_block_script_assets() function. The function uses st

CVE-2026-4979
Modérée 5.0

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to insufficient URL origin validation in the process_image_crop() me

CVE-2026-3358
Modérée 5.4

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course enrollment in all versions up to, and including, 3.9.7. This is due to missing post_status validation in the `enroll_now()` and `course_enrollment()` functions. Both enrollment endp

CVE-2026-3371
Modérée 4.3

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.9.7. This is due to missing authorization checks in the `save_course_content_order()` private method, which is called unconditionally by

CVE-2026-3498
Modérée 6.4

The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute in all versions up to, and including, 2.2.15. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-l

EDB-52505
Modérée

[webapps] RomM 4.4.0 - XSS_CSRF Chain

EDB-52501
Modérée

[local] 7-Zip 24.00 - Directory Traversal

EDB-52474
Modérée

[webapps] aiohttp 3.9.1 - directory traversal PoC

EDB-52471
Modérée

[webapps] Piranha CMS 12.0 - Stored XSS in Text Block

EDB-52470
Modérée

[webapps] RPi-Jukebox-RFID 2.8.0 - Stored Cross-Site Scripting (XSS)

EDB-52459
Modérée

[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)