Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 11

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-59669 Multiple vulnerabilities in the Repasat application Repasat Repasat application Medium 4.8 2026-10-02 08:40:53 Deep Dive
CVE-2026-91784 Argument Injection leading to arbitrary process termination in gotop cjbassi gotop Medium 4.8 2026-10-02 08:38:43 Deep Dive
CVE-2026-18036 NTRU leaks private key information by reducing secret values with a non-constant-time integer division Legion of the Bouncy Castle Inc. BC-JAVA High 8.2 2026-10-02 07:54:16 Deep Dive
CVE-2026-94432 Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter latepoint Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress Medium 5.3 2026-10-02 07:39:29 Deep Dive
CVE-2026-97637 JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response parorrey JSON API Auth Critical 9.8 2026-10-02 07:39:29 Deep Dive
CVE-2026-97338 Download Manager <= 3.3.70 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name codename065 Download Manager Medium 6.4 2026-10-02 07:39:29 Deep Dive
CVE-2026-95670 No External Links <= 5.2.0 - Unauthenticated Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect mihdan No External Links High 7.2 2026-10-02 07:39:28 Deep Dive
CVE-2026-96647 Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 6.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lsd[remark]' Parameter webilia Listdom: AI-powered Business Directory with Classifieds Ads Listings Medium 6.4 2026-10-02 07:39:28 Deep Dive
CVE-2026-97634 Event Tickets and Registration <= 5.29.5 - Authenticated (Contributor+) SQL Injection via 'orderby' Parameter stellarwp Event Tickets and Registration Medium 6.5 2026-10-02 07:39:28 Deep Dive
CVE-2026-100107 Kubio AI Page Builder <= 2.9.2 - Unauthenticated Stored Cross-Site Scripting via SVG Comment Content (KSES Allowlist Bypass) extendthemes Kubio AI Page Builder High 7.2 2026-10-02 07:39:27 Deep Dive
CVE-2026-93756 Smash Balloon Social Post Feed <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via Facebook Comment Message in Admin Builder Preview smub Smash Balloon Social Post Feed – Simple Social Feeds for WordPress High 7.2 2026-10-02 07:39:27 Deep Dive
CVE-2026-96871 Mang Board <= 2.4.2 - Unauthenticated Stored Cross-Site Scripting via 'data_type' Parameter kitae-park Mang Board High 7.2 2026-10-02 07:39:27 Deep Dive
CVE-2026-97342 JetFormBuilder <= 3.6.5.4 - Unauthenticated Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action jetmonsters JetFormBuilder — Dynamic Blocks Form Builder High 7.2 2026-10-02 07:39:26 Deep Dive
CVE-2026-103426 Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter Relevanssi Relevanssi Premium High 7.2 2026-10-02 07:39:25 Deep Dive
CVE-2026-96566 Newsletter <= 9.4.0 - Unauthenticated Stored Cross-Site Scripting via 'np1' Custom Field Parameter satollo Newsletter – Send awesome emails from WordPress High 7.2 2026-10-02 07:39:25 Deep Dive
CVE-2026-102002 Otter Blocks <= 3.2.6 - Authenticated (Subscriber+) Sensitive Information Exposure in Form Submissions Dashboard Widget themeisle Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Low 3.1 2026-10-02 07:39:24 Deep Dive
CVE-2026-12951 MultiVendorX <= 5.0.18 - Authenticated (Store Manager+) SQL Injection via 'order_by' Parameter wcmp MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions Medium 6.5 2026-10-02 07:39:24 Deep Dive
CVE-2026-100182 Download Monitor <= 5.2.10 - Unauthenticated Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor wpchill Download Monitor High 7.2 2026-10-02 07:39:24 Deep Dive
CVE-2026-102772 CMB2 <= 2.13.1 - Unauthenticated Stored Cross-Site Scripting via 'textarea_code' Field jtsternberg CMB2 High 7.2 2026-10-02 07:39:23 Deep Dive
CVE-2026-97641 Relevanssi <= 4.28.3 - Unauthenticated Stored Cross-Site Scripting via Comment Content comesio Relevanssi – A Better Search High 7.2 2026-10-02 07:39:23 Deep Dive