İçeriğe atla
Noroxi

Mitchell

Patchstack Bug Bounty Program

10 kredili kayıt · son 12 ayda 10 · 0 tanesi CISA KEV’de

Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.

Kredili kayıtlar

Araştırmacılar
  • CVE-2026-13770
    25İzleyin

    AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_ams_license_key AJAX Handler

    OrtaCVSS 6,4İstismar yokEPSS %0

    appmysite · appmysite – wordpress & woocommerce mobile app builder (no-code android & ios app maker)19 Eyl 2026

  • CVE-2026-14855
    25İzleyin

    RT Mega Menu <= 1.5.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via rtmega_update_menu_options AJAX Action

    OrtaCVSS 6,4İstismar yokEPSS %0

    themewant · rt mega menu – mega menu builder for elementor & gutenberg17 Eyl 2026

  • CVE-2026-12000
    30İzleyin

    Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API

    YüksekCVSS 7,5İstismar yokEPSS %1

    cyberlord92 · page and post restriction5 Ağu 2026

  • CVE-2026-66473
    30İzleyin

    WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    xendit · xendit payment27 Tem 2026

  • CVE-2026-59534
    30İzleyin

    WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    aurovrata venet · post my cf7 form27 Tem 2026

  • CVE-2026-59554
    30İzleyin

    WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    ziina · ziina23 Tem 2026

  • CVE-2026-57419
    26İzleyin

    WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability

    OrtaCVSS 6,5İstismar yokEPSS %0

    fahad mahmood · stock locations for woocommerce13 Tem 2026

  • CVE-2026-12103
    17İzleyin

    Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

    OrtaCVSS 4,3İstismar yokEPSS %0

    subratamal · wallet for woocommerce11 Tem 2026

  • CVE-2026-14249
    30İzleyin

    Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter

    YüksekCVSS 7,5İstismar yokEPSS %1

    emarket-design · request a quote – quote forms for any wordpress site2 Tem 2026

  • CVE-2026-49061
    30İzleyin

    WordPress WPC Product Options for WooCommerce plugin <= 3.2.1 - Arbitrary File Download vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %1

    wpclever · wpc product options for woocommerce15 Haz 2026