| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-0589 | code-projects Online Product Reservation System Administration Backend improper authentication | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-05 12:02:06 | Deep Dive |
| CVE-2026-0586 | code-projects Online Product Reservation System prod.php cross site scripting | code-projects | Online Product Reservation System | Medium | 4.3 | 2026-01-05 10:32:06 | Deep Dive |
| CVE-2026-0585 | code-projects Online Product Reservation System GET Parameter order_view.php sql injection | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-05 10:02:07 | Deep Dive |
| CVE-2026-0584 | code-projects Online Product Reservation System left_cart.php sql injection | code-projects | Online Product Reservation System | Medium | 6.3 | 2026-01-05 09:32:06 | Deep Dive |
| CVE-2026-0583 | code-projects Online Product Reservation System User Login login.php sql injection | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-05 09:02:06 | Deep Dive |
| CVE-2026-0579 | code-projects Online Product Reservation System POST Parameter edit.php sql injection | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-04 12:32:08 | Deep Dive |
| CVE-2026-0578 | code-projects Online Product Reservation System delete.php sql injection | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-04 12:02:08 | Deep Dive |
| CVE-2026-0577 | code-projects Online Product Reservation System prod.php unrestricted upload | code-projects | Online Product Reservation System | Medium | 6.3 | 2026-01-04 09:32:07 | Deep Dive |
| CVE-2026-0576 | code-projects Online Product Reservation System Parameter prod.php sql injection | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-04 09:02:06 | Deep Dive |
| CVE-2026-0575 | code-projects Online Product Reservation System Administrator Login adminlogin.php sql injection | code-projects | Online Product Reservation System | High | 7.3 | 2026-01-04 06:02:06 | Deep Dive |
| CVE-2025-15248 | sunhailin12315 product-review 商品评价系统 Write a Review cross site scripting | sunhailin12315 | product-review 商品评价系统 | Low | 3.5 | 2025-12-30 12:32:11 | Deep Dive |
| CVE-2025-69027 | WordPress Product Delivery Date for WooCommerce – Lite plugin <= 3.2.0 - Broken Access Control vulnerability | tychesoftwares | Product Delivery Date for WooCommerce – Lite | Medium | 5.3 | 2025-12-30 10:47:56 | Deep Dive |
| CVE-2025-68994 | WordPress Product Loops for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability | XforWooCommerce | Product Loops for WooCommerce | Medium | 5.3 | 2025-12-30 10:47:51 | Deep Dive |
| CVE-2025-23550 | WordPress Product Puller plugin <= 1.5.1 - Reflected Cross Site Scripting (XSS) vulnerability | Kemal YAZICI | Product Puller | High | 7.1 | 2025-12-29 23:50:09 | Deep Dive |
| CVE-2023-52210 | WordPress Product Delivery Date for WooCommerce – Lite plugin <= 2.7.0 - Broken Access Control vulnerability | Tyche softwares | Product Delivery Date for WooCommerce – Lite | Medium | 5.3 | 2025-12-23 12:02:46 | Deep Dive |
| CVE-2025-12398 | Product Table for WooCommerce <= 5.0.8 - Reflected Cross-Site Scripting | codersaiful | Product Table for WooCommerce | Medium | 6.1 | 2025-12-21 03:20:05 | Deep Dive |
| CVE-2025-13231 | Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Server-Side Request Forgery via Race Condition | radykal | Fancy Product Designer | Medium | 6.5 | 2025-12-16 08:20:24 | Deep Dive |
| CVE-2025-13439 | Fancy Product Designer | WooCommerce WordPress <= 6.4.8 - Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter | radykal | Fancy Product Designer | Medium | 5.9 | 2025-12-16 07:21:06 | Deep Dive |
| CVE-2025-12570 | Fancy Product Designer <= 6.4.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload | radykal | Fancy Product Designer | High | 7.2 | 2025-12-12 06:32:57 | Deep Dive |
| CVE-2025-13314 | Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.6 - Missing Authorization to Unauthenticated Plugin Settings Modification | markutos987 | Filter Plus – Product Filter & WordPress Filter | Medium | 5.3 | 2025-12-12 03:20:57 | Deep Dive |