Anwendungssicherheit
🟡 CVE-2026-16090: Medium Schwachstelle
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to...
🟡 CVE-2026-15950: Medium Schwachstelle
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for...
🟡 CVE-2026-15662: Medium Schwachstelle
The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
🟡 CVE-2026-15649: Medium Schwachstelle
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in...
🟡 CVE-2026-15645: Medium Schwachstelle
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'nav' Shortcode Attribute...
🟡 CVE-2026-15644: Medium Schwachstelle
The Powerkit – Supercharge your WordPress Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute...
🟡 CVE-2026-13458: Medium Schwachstelle
The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes in all...
🟡 CVE-2026-67292: Medium Schwachstelle
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a...
🟡 CVE-2026-2411: Medium Schwachstelle
Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ,...
🟡 CVE-2026-6453: Medium Schwachstelle
The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This...