| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Simple File List | ≤ 6.3.11 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Simple File List | 0 ~ 6.3.11 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14826 | Quiz And Survey Master < 11.2.4 - Contributor+ Cross-Quiz Email and Results Configuration | |
| CVE-2026-18031 | TabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment Callback | |
| CVE-2026-17565 | Animation Addons for Elementor < 2.7.2 - Unauthenticated Server-Side Request Forgery | |
| CVE-2026-15253 | Easy Media Replace <= 0.2.0 - Author+ Stored XSS via Attachment Title | |
| CVE-2026-16058 | YayCurrency < 3.3.5 - Unauthenticated Order and Vendor Financial Data Disclosure via Dokan | |
| CVE-2026-16570 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Reflected XSS via Facebook OAuth Callba | |
| CVE-2026-16616 | Simple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path Travers | |
| CVE-2026-14825 | Quiz And Survey Master < 11.2.4 - Contributor+ Arbitrary Quiz Text Settings Update via IDO | |
| CVE-2026-14334 | Booking calendar, Appointment Booking System <= 3.2.36 - Unauthenticated Stored XSS via SV | |
| CVE-2026-14861 | User Verification <= 2.0.47 - Unauthenticated Arbitrary Account Lockout via IDOR | |
| CVE-2026-16979 | SmartCrawl < 3.16.3 - Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key En | |
| CVE-2026-14287 | TenWeb Speed Optimizer < 2.33.5 - Unauthenticated Stored XSS via Critical CSS Token Bypass | |
| CVE-2026-14196 | WCFM Marketplace < 3.8.1 - Store Vendor+ Cross-Vendor Review Deletion and Status Update vi | |
| CVE-2026-13174 | Eventin < 4.1.21 - Contributor+ Speaker Account Deletion via IDOR | |
| CVE-2026-13175 | Eventin < 4.1.21 - Contributor+ Schedule Deletion and Modification via IDOR | |
| CVE-2026-11565 | Advanced File Manager < 5.4.13 - Authenticated Arbitrary File Read and Write via fma_load_ | |
| CVE-2026-12983 | Dinatur <= 1.18 - Unauthenticated SQL Injection via Column Name Injection | |
| CVE-2026-13169 | Eventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeo | |
| CVE-2026-13173 | Eventin < 4.1.21 - Contributor+ User Role and Meta Modification via Speaker Creation | |
| CVE-2026-18777 | TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Arbitrary Appointment Status Chan |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet