CVE-2026-66428
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
直近表示から外れた情報を確認できます。診断結果とは別情報として扱います。
Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to arbitrary locations the current user has write access, including the Windows Startup folder, enabling persistent code execution on the next user login.
Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.
Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.
Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versions.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.
Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1 - Improper validation of various parameters in the media manager search and date filters lead to an SQL injection vector.