| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-15674 | Low | 0.18 | 2.7 | 0.00 | Aug 6, 2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read… | ||
| CVE-2025-14561 | — | Cri | 0.52 | 9.0 | 0.00 | Aug 6, 2026 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user… | |
| CVE-2025-12317 | Med | 0.33 | 5.0 | 0.00 | Aug 6, 2026 | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have… | ||
| CVE-2024-6541 | — | Med | 0.37 | 6.8 | 0.00 | Aug 6, 2026 | The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness… | |
| CVE-2024-39024 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2026 | In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. | ||
| CVE-2026-16633 | hig | 0.45 | — | — | Aug 6, 2026 | ### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting… | ||
| CVE-2026-68750 | Hig | 0.42 | 7.5 | 0.01 | Aug 6, 2026 | Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of… | ||
| CVE-2026-68749 | Hig | 0.42 | 7.5 | 0.01 | Aug 6, 2026 | Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitizeEx.Scrubber.CSS.scrub/1… | ||
| CVE-2026-68747 | Med | 0.33 | 6.1 | 0.00 | Aug 6, 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a remote stylesheet, into a… | ||
| CVE-2026-66843 | Med | 0.33 | 6.1 | 0.01 | Aug 6, 2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an element in sanitized HTML. object is… | ||
| CVE-2026-66829 | Med | 0.33 | 6.1 | 0.01 | Aug 6, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a element in sanitized HTML.… | ||
| CVE-2026-66370 | Med | 0.33 | 6.1 | 0.00 | Aug 6, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the… | ||
| CVE-2026-5423 | — | Hig | 0.46 | — | 0.01 | Aug 6, 2026 | @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection… | |
| CVE-2026-53985 | Hig | 0.42 | 7.5 | 0.01 | Aug 6, 2026 | Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service… | ||
| CVE-2026-53977 | Hig | 0.42 | 7.5 | 0.01 | Aug 6, 2026 | OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express… | ||
| CVE-2026-43622 | Hig | 0.44 | 7.8 | 0.00 | Aug 6, 2026 | llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger… | ||
| CVE-2026-3430 | Hig | 0.56 | 8.6 | 0.00 | Aug 6, 2026 | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | ||
| CVE-2026-19047 | Med | 0.35 | 5.3 | 0.01 | Aug 6, 2026 | A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in… | ||
| CVE-2026-19046 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2026 | A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name… | ||
| CVE-2026-18427 | Hig | 0.49 | 7.5 | 0.01 | Aug 6, 2026 | @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching… | ||
| CVE-2026-18359 | Hig | 0.55 | 8.5 | 0.00 | Aug 6, 2026 | Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or… | ||
| CVE-2026-18277 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the… | ||
| CVE-2026-18276 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls… | ||
| CVE-2026-18275 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied… | ||
| CVE-2026-18258 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2026 | Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request… | ||
| CVE-2026-70646 | Hig | 0.42 | 7.5 | 0.01 | Aug 6, 2026 | aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON… | ||
| CVE-2026-70637 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2026 | LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker… | ||
| CVE-2026-67261 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary… | ||
| CVE-2026-66712 | Hig | 0.49 | 7.5 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions. | ||
| CVE-2026-66711 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | ||
| CVE-2026-66710 | Hig | 0.53 | 8.1 | 0.00 | Aug 6, 2026 | Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions. | ||
| CVE-2026-66709 | Cri | 0.59 | 9.1 | 0.01 | Aug 6, 2026 | Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions. | ||
| CVE-2026-66708 | Hig | 0.53 | 8.2 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | ||
| CVE-2026-66707 | Hig | 0.39 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | ||
| CVE-2026-66706 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2026 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | ||
| CVE-2026-66705 | Hig | 0.39 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | ||
| CVE-2026-66703 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | ||
| CVE-2026-66702 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | ||
| CVE-2026-66701 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | ||
| CVE-2026-66699 | Med | 0.27 | 5.3 | 0.00 | Aug 6, 2026 | Custom role Broken Access Control in Dokan <= 5.0.10 versions. | ||
| CVE-2026-66696 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | ||
| CVE-2026-66695 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | ||
| CVE-2026-66694 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | ||
| CVE-2026-66692 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2026 | Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions. | ||
| CVE-2026-66690 | Hig | 0.46 | 7.1 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | ||
| CVE-2026-66688 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | ||
| CVE-2026-66686 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. | ||
| CVE-2026-66685 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | ||
| CVE-2026-66684 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions. | ||
| CVE-2026-66683 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2026 | Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. |
- risk 0.18cvss 2.7epss 0.00
The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read…
- risk 0.52cvss 9.0epss 0.00
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user…
- risk 0.33cvss 5.0epss 0.00
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have…
- risk 0.37cvss 6.8epss 0.00
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness…
- risk 0.57cvss 8.8epss 0.01
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
- risk 0.45cvss —epss —
### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting…
- risk 0.42cvss 7.5epss 0.01
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of…
- risk 0.42cvss 7.5epss 0.01
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitizeEx.Scrubber.CSS.scrub/1…
- risk 0.33cvss 6.1epss 0.00
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a remote stylesheet, into a…
- risk 0.33cvss 6.1epss 0.01
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an element in sanitized HTML. object is…
- risk 0.33cvss 6.1epss 0.01
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a element in sanitized HTML.…
- risk 0.33cvss 6.1epss 0.00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the…
- risk 0.46cvss —epss 0.01
@neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection…
- risk 0.42cvss 7.5epss 0.01
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service…
- risk 0.42cvss 7.5epss 0.01
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express…
- risk 0.44cvss 7.8epss 0.00
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger…
- risk 0.56cvss 8.6epss 0.00
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
- risk 0.35cvss 5.3epss 0.01
A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in…
- risk 0.21cvss 3.3epss 0.00
A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name…
- risk 0.49cvss 7.5epss 0.01
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching…
- risk 0.55cvss 8.5epss 0.00
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or…
- risk 0.46cvss 7.1epss 0.00
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the…
- risk 0.28cvss 4.3epss 0.00
Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls…
- risk 0.42cvss 6.5epss 0.00
Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied…
- risk 0.57cvss 8.8epss 0.01
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request…
- risk 0.42cvss 7.5epss 0.01
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON…
- risk 0.38cvss 5.9epss 0.00
LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker…
- risk 0.64cvss 9.8epss 0.02
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
- risk 0.46cvss 7.1epss 0.00
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
- risk 0.53cvss 8.1epss 0.00
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
- risk 0.59cvss 9.1epss 0.01
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
- risk 0.53cvss 8.2epss 0.00
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
- risk 0.39cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
- risk 0.38cvss 5.9epss 0.00
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
- risk 0.39cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
- risk 0.27cvss 5.3epss 0.00
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
- risk 0.28cvss 4.3epss 0.00
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
- risk 0.28cvss 4.3epss 0.00
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
- risk 0.46cvss 7.1epss 0.00
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
- risk 0.42cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
- risk 0.42cvss 6.5epss 0.00
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
- risk 0.34cvss 5.3epss 0.00
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.