Anwendungssicherheit
🟡 CVE-2026-12754: Medium Schwachstelle
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter...
🟡 CVE-2026-5220: Medium Schwachstelle
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS....
🟡 CVE-2026-10095: Medium Schwachstelle
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all...
🟡 CVE-2026-13733: Medium Schwachstelle
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up...
🟡 CVE-2026-12732: Medium Schwachstelle
The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to,...
🟡 CVE-2026-13454: Medium Schwachstelle
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions...
🟠 CVE-2026-12142: High Schwachstelle
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array...
🟠 CVE-2026-50043: High Schwachstelle
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this...
🟠 CVE-2026-11883: High Schwachstelle
The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an...
🟠 CVE-2026-14181: High Luecke in Fastify Fastify\/Middie
@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request...