PRISM
80 kredili kayıt · son 12 ayda 80 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
24İzleyin | CVE-2026-15094Kavram kanıtı | WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameterthimpress · wp hotel booking · CWE-79 | Orta6,1 | — | %0,7 | 17 Tem 2026 |
25İzleyin | CVE-2026-15759İstismar yok | ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributesthemeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat form · CWE-79 | Orta6,4 | — | %0,3 | 17 Tem 2026 |
19İzleyin | CVE-2026-15457İstismar yok | Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameterthemeum · kirki – freeform page builder, website builder & customizer · CWE-22 | Orta4,9 | — | %1,1 | 17 Tem 2026 |
17İzleyin | CVE-2026-15349İstismar yok | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creatwedevs · erp: complete hr, accounting & crm suite built for woocommerce · CWE-862 | Orta4,3 | — | %0,5 | 17 Tem 2026 |
28İzleyin | CVE-2026-15395İstismar yok | Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Valuewpchill · kali forms — contact form & drag-and-drop builder · CWE-79 | Yüksek7,2 | — | %0,4 | 17 Tem 2026 |
19İzleyin | CVE-2026-15727İstismar yok | WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameterxylus · wp bulk delete · CWE-89 | Orta4,9 | — | %0,6 | 16 Tem 2026 |
19İzleyin | CVE-2026-15651İstismar yok | WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameterjgwhite33 · wp tripadvisor review slider · CWE-89 | Orta4,9 | — | %0,5 | 16 Tem 2026 |
17İzleyin | CVE-2026-15610İstismar yok | WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Functionquantumcloud · wpbot – ai chatbot for live support, lead generation, ai services · CWE-862 | Orta4,3 | — | %0,4 | 16 Tem 2026 |
17İzleyin | CVE-2026-15407İstismar yok | Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Actionthemifyme · themify builder · CWE-862 | Orta4,3 | — | %0,5 | 16 Tem 2026 |
17İzleyin | CVE-2026-15350İstismar yok | The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameterkevp75 · the cache purger · CWE-862 | Orta4,3 | — | %0,4 | 16 Tem 2026 |
17İzleyin | CVE-2026-15324İstismar yok | SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameterphppoet · sysbasics customize my account for woocommerce – live my account customizer · CWE-79 | Orta4,4 | — | %0,3 | 16 Tem 2026 |
21İzleyin | CVE-2026-15106İstismar yok | WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameterquantumcloud · wpbot – ai chatbot for live support, lead generation, ai services · CWE-862 | Orta5,3 | — | %0,5 | 16 Tem 2026 |
35İzleyin | CVE-2026-15103İstismar yok | WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parametergetwpfunnels · wpfunnels – funnel builder for woocommerce with checkout & one click upsell · CWE-269 | Yüksek8,8 | — | %0,6 | 16 Tem 2026 |
25İzleyin | CVE-2026-15099İstismar yok | WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attributewpdelicious · wp delicious – recipe plugin for food bloggers (formerly delicious recipes) · CWE-79 | Orta6,4 | — | %0,3 | 16 Tem 2026 |
26İzleyin | CVE-2026-13767İstismar yok | Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameterexpresstech · quiz and survey master (qsm) – quiz maker & survey maker · CWE-89 | Orta6,5 | — | %0,4 | 16 Tem 2026 |
25İzleyin | CVE-2026-13755İstismar yok | Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attributetickera · tickera – sell tickets & manage events · CWE-79 | Orta6,4 | — | %0,4 | 16 Tem 2026 |
26İzleyin | CVE-2026-13754İstismar yok | Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parametertickera · tickera – sell tickets & manage events · CWE-89 | Orta6,5 | — | %0,4 | 16 Tem 2026 |
19İzleyin | CVE-2026-15458İstismar yok | SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parametercleverplugins · seo booster · CWE-89 | Orta4,9 | — | %0,4 | 16 Tem 2026 |
19İzleyin | CVE-2026-15445İstismar yok | SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parametercleverplugins · seo booster · CWE-89 | Orta4,9 | — | %0,4 | 16 Tem 2026 |
24İzleyin | CVE-2026-15306İstismar yok | Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameterrextheme · product feed manager for woocommerce – sell on 200+ online marketplaces · CWE-79 | Orta6,1 | — | %0,4 | 16 Tem 2026 |
25İzleyin | CVE-2026-15652İstismar yok | Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attributeshapedplugin · easy accordion – ai-powered faq & accordion blocks, product faq · CWE-79 | Orta6,4 | — | %0,3 | 16 Tem 2026 |
17İzleyin | CVE-2026-15336İstismar yok | Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parametercatchplugins · catch themes demo import · CWE-862 | Orta4,3 | — | %0,4 | 16 Tem 2026 |
17İzleyin | CVE-2026-13005İstismar yok | MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Settingmxchat · mxchat – ai chatbot & content generation for wordpress · CWE-79 | Orta4,4 | — | %0,3 | 16 Tem 2026 |
26İzleyin | CVE-2026-12941İstismar yok | MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameterwcmp · multivendorx – woocommerce multivendor marketplace ai powered solutions · CWE-89 | Orta6,5 | — | %0,4 | 16 Tem 2026 |
30İzleyin | CVE-2026-12753İstismar yok | Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameterthemehunk · advance product search- voice & ajax search for woocommerce · CWE-89 | Yüksek7,5 | — | %0,5 | 16 Tem 2026 |
- CVE-2026-1509424İzleyin
WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter
OrtaCVSS 6,1Kavram kanıtıEPSS %1thimpress · wp hotel booking17 Tem 2026
- CVE-2026-1575925İzleyin
ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes
OrtaCVSS 6,4İstismar yokEPSS %0themeatelier · chathelp – click to chat button, woocommerce chat to order & floating chat form17 Tem 2026
- CVE-2026-1545719İzleyin
Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter
OrtaCVSS 4,9İstismar yokEPSS %1themeum · kirki – freeform page builder, website builder & customizer17 Tem 2026
- CVE-2026-1534917İzleyin
ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creat
OrtaCVSS 4,3İstismar yokEPSS %0wedevs · erp: complete hr, accounting & crm suite built for woocommerce17 Tem 2026
- CVE-2026-1539528İzleyin
Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
YüksekCVSS 7,2İstismar yokEPSS %0wpchill · kali forms — contact form & drag-and-drop builder17 Tem 2026
- CVE-2026-1572719İzleyin
WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter
OrtaCVSS 4,9İstismar yokEPSS %1xylus · wp bulk delete16 Tem 2026
- CVE-2026-1565119İzleyin
WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter
OrtaCVSS 4,9İstismar yokEPSS %0jgwhite33 · wp tripadvisor review slider16 Tem 2026
- CVE-2026-1561017İzleyin
WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function
OrtaCVSS 4,3İstismar yokEPSS %0quantumcloud · wpbot – ai chatbot for live support, lead generation, ai services16 Tem 2026
- CVE-2026-1540717İzleyin
Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action
OrtaCVSS 4,3İstismar yokEPSS %0themifyme · themify builder16 Tem 2026
- CVE-2026-1535017İzleyin
The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter
OrtaCVSS 4,3İstismar yokEPSS %0kevp75 · the cache purger16 Tem 2026
- CVE-2026-1532417İzleyin
SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter
OrtaCVSS 4,4İstismar yokEPSS %0phppoet · sysbasics customize my account for woocommerce – live my account customizer16 Tem 2026
- CVE-2026-1510621İzleyin
WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter
OrtaCVSS 5,3İstismar yokEPSS %0quantumcloud · wpbot – ai chatbot for live support, lead generation, ai services16 Tem 2026
- CVE-2026-1510335İzleyin
WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter
YüksekCVSS 8,8İstismar yokEPSS %1getwpfunnels · wpfunnels – funnel builder for woocommerce with checkout & one click upsell16 Tem 2026
- CVE-2026-1509925İzleyin
WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute
OrtaCVSS 6,4İstismar yokEPSS %0wpdelicious · wp delicious – recipe plugin for food bloggers (formerly delicious recipes)16 Tem 2026
- CVE-2026-1376726İzleyin
Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter
OrtaCVSS 6,5İstismar yokEPSS %0expresstech · quiz and survey master (qsm) – quiz maker & survey maker16 Tem 2026
- CVE-2026-1375525İzleyin
Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute
OrtaCVSS 6,4İstismar yokEPSS %0tickera · tickera – sell tickets & manage events16 Tem 2026
- CVE-2026-1375426İzleyin
Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter
OrtaCVSS 6,5İstismar yokEPSS %0tickera · tickera – sell tickets & manage events16 Tem 2026
- CVE-2026-1545819İzleyin
SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter
OrtaCVSS 4,9İstismar yokEPSS %0cleverplugins · seo booster16 Tem 2026
- CVE-2026-1544519İzleyin
SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
OrtaCVSS 4,9İstismar yokEPSS %0cleverplugins · seo booster16 Tem 2026
- CVE-2026-1530624İzleyin
Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter
OrtaCVSS 6,1İstismar yokEPSS %0rextheme · product feed manager for woocommerce – sell on 200+ online marketplaces16 Tem 2026
- CVE-2026-1565225İzleyin
Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute
OrtaCVSS 6,4İstismar yokEPSS %0shapedplugin · easy accordion – ai-powered faq & accordion blocks, product faq16 Tem 2026
- CVE-2026-1533617İzleyin
Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter
OrtaCVSS 4,3İstismar yokEPSS %0catchplugins · catch themes demo import16 Tem 2026
- CVE-2026-1300517İzleyin
MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting
OrtaCVSS 4,4İstismar yokEPSS %0mxchat · mxchat – ai chatbot & content generation for wordpress16 Tem 2026
- CVE-2026-1294126İzleyin
MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter
OrtaCVSS 6,5İstismar yokEPSS %0wcmp · multivendorx – woocommerce multivendor marketplace ai powered solutions16 Tem 2026
- CVE-2026-1275330İzleyin
Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter
YüksekCVSS 7,5İstismar yokEPSS %1themehunk · advance product search- voice & ajax search for woocommerce16 Tem 2026