| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | RegistrationMagic | < 6.0.9.4 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | RegistrationMagic | 0 ~ 6.0.9.4 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15054 | Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission | |
| CVE-2026-15257 | RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modificatio | |
| CVE-2026-15240 | Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrat | |
| CVE-2026-15235 | Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX | |
| CVE-2026-15153 | WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search | |
| CVE-2026-14318 | GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings | |
| CVE-2026-14231 | LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts | |
| CVE-2026-14207 | LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information | |
| CVE-2026-12687 | ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID | |
| CVE-2026-15250 | LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funn | |
| CVE-2026-14602 | Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter | |
| CVE-2026-14923 | Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification | |
| CVE-2026-14223 | Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR | |
| CVE-2026-14226 | Easy Appointments <= 3.12.26 - Subscriber+ Sensitive Information Disclosure via REST Appoi | |
| CVE-2026-14592 | WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr | |
| CVE-2026-14222 | Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization | |
| CVE-2026-14221 | Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via | |
| CVE-2026-14188 | Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure | |
| CVE-2026-13143 | WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN | |
| CVE-2026-14239 | Tourmaster < 5.4.8 - Stored XSS via CSRF |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet