Anwendungssicherheit
🟠 CVE-2026-81289: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar
🟠 CVE-2026-81288: High Schwachstelle
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce
🟠 CVE-2026-82883: High Schwachstelle
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This...
🟠 CVE-2026-12865: High Schwachstelle
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute...
🟠 CVE-2026-75528: High Schwachstelle
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author URL / Link Log...
🟠 CVE-2026-81774: High Schwachstelle
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment
🟠 CVE-2026-19219: High Schwachstelle
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor...
🟠 CVE-2026-81772: High Schwachstelle
Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles
🟠 CVE-2026-81283: High Schwachstelle
Subscriber PHP Object Injection in WP User Frontend
🟠 CVE-2026-14828: High Schwachstelle
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are...