Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Vulnerability List - Page 13

CVE ID Title Vendor Product Severity CVSS Score Published At AI Analysis
CVE-2026-93697 WHM Mass Modify Accounts存储型XSS漏洞 Webpros cPanel - - 2026-10-02 06:20:44 Deep Dive
CVE-2026-93698 Multilang adminbin验证不足致任意命令执行 Webpros cPanel - - 2026-10-02 06:20:34 Deep Dive
CVE-2026-97317 Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Disclosure via Giveaway Page Unknown Giveaways and Contests by RafflePress - - 2026-10-02 06:00:27 Deep Dive
CVE-2026-97318 Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter Unknown Giveaways and Contests by RafflePress - - 2026-10-02 06:00:27 Deep Dive
CVE-2026-94298 BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter Unknown BuildKit - - 2026-10-02 06:00:26 Deep Dive
CVE-2026-91023 Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured Unknown Motors - - 2026-10-02 06:00:26 Deep Dive
CVE-2026-91022 Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color Unknown Motors - - 2026-10-02 06:00:26 Deep Dive
CVE-2026-13718 Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content Unknown Tabs Responsive - - 2026-10-02 06:00:25 Deep Dive
CVE-2026-85016 Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Parameter Unknown Unlimited Elements for Elementor - - 2026-10-02 06:00:25 Deep Dive
CVE-2026-90988 Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum Unknown Request a Quote - - 2026-10-02 06:00:25 Deep Dive
CVE-2026-91828 OMGF < 6.3.11 - Unauthenticated DoS via do_optimize Unknown OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. - - 2026-10-02 06:00:25 Deep Dive
CVE-2026-85004 Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect Unknown Popup Maker - - 2026-10-02 06:00:24 Deep Dive
CVE-2026-81740 Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Callback Unknown Paytm Payment Gateway - - 2026-10-02 06:00:24 Deep Dive
CVE-2026-15896 Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter WebRehab Super Forms – Drag & Drop Form Builder Critical 9.1 2026-10-02 05:30:19 Deep Dive
CVE-2026-92174 SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter gpriday SiteOrigin Widgets Bundle High 7.5 2026-10-02 05:30:18 Deep Dive
CVE-2026-90438 Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder High 7.2 2026-10-02 05:30:18 Deep Dive
CVE-2026-78471 Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name optimizingmatters Autoptimize Medium 5.4 2026-10-02 05:30:18 Deep Dive
CVE-2026-15897 Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login WebRehab Super Forms – Drag & Drop Form Builder High 8.8 2026-10-02 05:30:17 Deep Dive
CVE-2026-92820 Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload SaturdayDrive Ninja Forms - File Uploads High 8.1 2026-10-02 05:30:16 Deep Dive
CVE-2026-84925 Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter ThemeFusion Avada | Website Builder For WordPress & WooCommerce Medium 6.1 2026-10-02 05:30:15 Deep Dive