Anwendungssicherheit
🟡 CVE-2024-58360: Medium Schwachstelle
stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers...
🟡 CVE-2026-15022: Medium Schwachstelle
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored...
🟡 CVE-2026-13767: Medium Schwachstelle
The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up...
🟡 CVE-2026-13754: Medium Schwachstelle
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's'...
🟡 CVE-2026-12684: Medium Schwachstelle
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of...
🟡 CVE-2026-12395: Medium Schwachstelle
The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in...
🟠 CVE-2026-7543: High Schwachstelle
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and...
🟠 CVE-2026-63305: High Schwachstelle
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated...
🟠 CVE-2026-63304: High Schwachstelle
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside...
🟠 CVE-2026-15008: High Schwachstelle
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file...