832 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2026-2687
Reading progressbar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2026-0997
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558

CVE-2026-0554
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 CWE-862 1 PoC

The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible for authenticated attackers, with Contributor-level access and above, to reset analytics for any NotificationX campaign, regardless of ownership.

CVE-2026-24692
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554

CVE-2026-1629
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-672 1 PoC

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580

CVE-2026-22912
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-601 1 PoC

Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users.

CVE-2026-1369
Conditional CAPTCHA Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Conditional CAPTCHA WordPress plugin through 4.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

CVE-2026-25783
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-1287 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586

CVE-2026-31150
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources.

CVE-2026-26233
Mattermost Web
4.3
MEDIUM
EPSS
0.1%
2026 CWE-400 1 PoC

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthenticated remote attackers to cause denial of service (server crash and restart) via HTTP/2 single packet attack with 100+ parallel login requests.. Mattermost Advisory ID: MMSA-2025-00566

CVE-2026-0658
Five Star Restaurant Reservations Web Windows
4.3
MEDIUM
EPSS
0.0%
2026 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks.

CVE-2026-26304
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which allows team members to create unauthorized runs via the playbook run API. Mattermost Advisory ID: MMSA-2025-00542

CVE-2026-22917
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.

CVE-2026-22892
Mattermost Web
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550

CVE-2026-2578
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-201 1 PoC

Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

CVE-2026-4265
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553

CVE-2026-1768
Devolutions Server General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-863 1 PoC

A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to access entries.This issue affects Devolutions Server: before 2025.3.15.

CVE-2026-2461
Mattermost General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-639 1 PoC

Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559

CVE-2026-26246
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2026 CWE-789 1 PoC

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00572

CVE-2026-22916
TDC-X401GL General
4.3
MEDIUM
EPSS
0.0%
2026 CWE-266 1 PoC

An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration.