69 Failles indexées
17 Critiques
14 Élevées
2 Ajoutées aujourd'hui

6 failles trouvées

filtres actifs
CVE-2026-31845
Critique 9.3

A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response without proper sanitiza

CVE-2026-5809
Élevée 7.1

The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. This is due to a two-step logic flaw: the topic_add() and topic_edit() action handlers accept arbitrary user-supplied data[*] arrays from $_REQUEST and store them as postmeta without

CVE-2026-5217
Élevée 7.2

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due to insufficient input sanitization and output escaping on the user-supplied 's' param

CVE-2026-4979
Modérée 5.0

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to blind Server-Side Request Forgery in all versions up to, and including, 1.2.58. This is due to insufficient URL origin validation in the process_image_crop() me

EDB-52460
Inconnue

[webapps] Pluck 4.7.7-dev2 - PHP Code Execution

EDB-52459
Modérée

[webapps] phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)