CVE-2026-65449
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
直近表示から外れた情報を確認できます。診断結果とは別情報として扱います。
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.