Anwendungssicherheit
🟠 CVE-2026-56256: High Schwachstelle
Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g., editing...
🟠 CVE-2026-56244: High Schwachstelle
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security...
🟠 CVE-2026-9643: High Schwachstelle
The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in...
🟠 CVE-2026-12100: High Schwachstelle
The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0...
🟠 CVE-2026-12095: High Schwachstelle
The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2...
🟠 CVE-2026-10092: High Schwachstelle
The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post...
🟠 CVE-2026-10091: High Schwachstelle
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all...
🟠 CVE-2026-9179: High Schwachstelle
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST...
🟠 CVE-2026-8705: High Schwachstelle
The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX...
🟠 CVE-2026-10735: High Schwachstelle
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin...