İçeriğe atla
Noroxi

Powpy

Patchstack Bug Bounty Program

37 kredili kayıt · son 12 ayda 37 · 0 tanesi CISA KEV’de

Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.

Kredili kayıtlar

Araştırmacılar
  • CVE-2026-1256
    25İzleyin

    YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input

    OrtaCVSS 6,4İstismar yokEPSS %0

    ysinnovations · ys leadgen – popup builder, popup maker & form builder for wordpress | lead generation, email marketing, sales, conversions, opt-ins & subscribers19 Eyl 2026

  • CVE-2026-1856
    25İzleyin

    Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label

    OrtaCVSS 6,4İstismar yokEPSS %0

    creavi · creavi appointment booking calendar19 Haz 2026

  • CVE-2025-14452
    28İzleyin

    WP Customer Reviews <= 3.7.5 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter

    YüksekCVSS 7,2İstismar yokEPSS %0

    bompus · wp customer reviews19 Şub 2026

  • CVE-2025-12707
    30İzleyin

    Library Management System <= 3.2.1 - Unauthenticated SQL Injection

    YüksekCVSS 7,5İstismar yokEPSS %0

    owthub · library management system19 Şub 2026

  • CVE-2026-1306
    40Planlayın

    midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    adminkov · midi-synth14 Şub 2026

  • CVE-2025-14610
    28İzleyin

    TableMaster for Elementor <= 1.3.6 - Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter

    YüksekCVSS 7,2İstismar yokEPSS %0

    bloompixel · tablemaster for elementor – advanced responsive tables for elementor28 Oca 2026

  • CVE-2026-0694
    25İzleyin

    SearchWiz <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title

    OrtaCVSS 6,4İstismar yokEPSS %0

    searchwiz · searchwiz14 Oca 2026

  • CVE-2025-14506
    25İzleyin

    ConvertForce Popup Builder <= 0.0.7 - Stored Cross-Site Scripting via entrance_animation

    OrtaCVSS 6,4İstismar yokEPSS %0

    imtiazrayhan · convertforce popup builder10 Oca 2026

  • CVE-2025-11453
    25İzleyin

    Header and Footer Scripts <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    OrtaCVSS 6,4İstismar yokEPSS %0

    anand_kumar · header and footer scripts9 Oca 2026

  • CVE-2025-14626
    25İzleyin

    QR Code for WooCommerce order emails, PDF invoices, packing slips <= 1.9.42 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode Attributes

    OrtaCVSS 6,4İstismar yokEPSS %0

    www15to · qr code for woocommerce order emails, pdf invoices, packing slips7 Oca 2026

  • CVE-2025-14453
    25İzleyin

    My Album Gallery <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style_css' Shortcode Attribute

    OrtaCVSS 6,4İstismar yokEPSS %0

    ruhul080 · my album gallery7 Oca 2026

  • CVE-2025-14153
    26İzleyin

    Page Expire Popup/Redirection for WordPress <= 1.0 - Authenticated (Author+) SQL Injection via 'id' Shortcode Attribute

    OrtaCVSS 6,5İstismar yokEPSS %0

    vikasratudi · page expire popup/redirection for wordpress6 Oca 2026

  • CVE-2025-49339
    17İzleyin

    WordPress Direct Payments WP plugin <= 1.3.2 - Broken Access Control vulnerability

    OrtaCVSS 4,3İstismar yokEPSS %0

    digages · direct payments wp31 Ara 2025

  • CVE-2025-49352
    17İzleyin

    WordPress Order Cancellation & Returns for WooCommerce plugin <= 1.1.10 - Insecure Direct Object References (IDOR) vulnerability

    OrtaCVSS 4,3İstismar yokEPSS %0

    yoohw studio · order cancellation & returns for woocommerce31 Ara 2025

  • CVE-2025-49356
    17İzleyin

    WordPress Orders Chat for WooCommerce plugin <= 1.2.0 - Broken Access Control vulnerability

    OrtaCVSS 4,3İstismar yokEPSS %0

    mykola lukin · orders chat for woocommerce31 Ara 2025

  • CVE-2025-49334
    21İzleyin

    WordPress MyD Delivery plugin <= 1.7.1 - Insecure Direct Object References (IDOR) vulnerability

    OrtaCVSS 5,3İstismar yokEPSS %0

    eduardo villão · myd delivery31 Ara 2025

  • CVE-2025-13693
    25İzleyin

    Image Photo Gallery Final Tiles Grid <= 3.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting

    OrtaCVSS 6,4İstismar yokEPSS %0

    wpchill · image photo gallery final tiles grid21 Ara 2025

  • CVE-2025-14003
    17İzleyin

    Image Gallery – Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification

    OrtaCVSS 4,3İstismar yokEPSS %0

    wpchill · modula image gallery – photo grid & video gallery15 Ara 2025

  • CVE-2025-14365
    21İzleyin

    Eyewear prescription form <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion

    OrtaCVSS 5,3İstismar yokEPSS %0

    dugudlabs · eyewear prescription form13 Ara 2025

  • CVE-2025-12109
    25İzleyin

    Header Footer Script Adder – Insert Code in Header, Body & Footer <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

    OrtaCVSS 6,4İstismar yokEPSS %0

    mahethekiller · header footer script adder – insert code in header, body & footer13 Ara 2025

  • CVE-2025-14068
    30İzleyin

    WPNakama <= 0.6.3 - Unauthenticated SQL Injection via 'order_by' Parameter

    YüksekCVSS 7,5İstismar yokEPSS %0

    qdonow · wpnakama – team and multi-client collaboration, editorial and project management12 Ara 2025

  • CVE-2025-14166
    21İzleyin

    WPMasterToolKit (WPMTK) <= 2.13.0 - Authenticated (Contributor+) Code Injection

    OrtaCVSS 5,3İstismar yokEPSS %0

    ludwigyou · wpmastertoolkit (wpmtk) – all in one plugin12 Ara 2025

  • CVE-2025-12783
    17İzleyin

    Premmerce Brands for WooCommerce <= 1.2.13 - Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update

    OrtaCVSS 4,3İstismar yokEPSS %0

    premmerce · premmerce brands for woocommerce12 Ara 2025

  • CVE-2025-12782
    17İzleyin

    Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering

    OrtaCVSS 4,3İstismar yokEPSS %0

    fastlinemedia · beaver builder4 Ara 2025

  • CVE-2025-13157
    21İzleyin

    QODE Wishlist for WooCommerce <= 1.2.7 - Unauthenticated Insecure Direct Object Reference to Wishlist Update

    OrtaCVSS 5,3İstismar yokEPSS %0

    qodeinteractive · qode wishlist for woocommerce27 Kas 2025