87 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2026-2687
Reading progressbar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-0554
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset analytics for any NotificationX campaign, regardless of ownership.

CVE-2026-1369
Conditional CAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2026-0658
Five Star Restaurant Reservations Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

CVE-2026-4512
reCaptcha by WebDesignBy Web Windows
3.5
LOW
EPSS
0.0%
2026 1 PoC

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context via the grecaptcha_js() function. This allows administrators on multisite installations (who do not have the unfiltered_html capability) to inject arbitrary JavaScript that executes for all visitors to the WordPress login page.

CVE-2026-0747
Remote Desktop Manager Windows
3.3
LOW
EPSS
0.0%
2026 CWE-200 1 PoC

Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical observation or screen sharing.

CVE-2026-1966
YugabyteDB Anywhere Windows
2.4
LOW
EPSS
0.0%
2026 CWE-522 1 PoC

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the configuration view could obtain LDAP credentials, potentially enabling unauthorized access to external directory services.