NVD CVEs — 本日公開 (5 件)
CVE-2026-13362 6.4 MEDIUM
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with cont
CVE-2026-15006 7.5 HIGH
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the conte
CVE-2026-15403 4.9 MEDIUM
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This m
CVE-2026-15414 8.8 HIGH
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$_POST` without an allowlist that excludes privileged
CVE-2026-7623 6.4 MEDIUM
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible f
GitHub Security Advisories — 本日公開 (12 件)
GHSA-x6w6-m8vc-m6cp
HIGH
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in...
GHSA-vvqx-954c-23g6
MEDIUM
The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is...
GHSA-j262-2rh9-xjv4
HIGH
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation...
GHSA-v59p-52gm-jwpr
MEDIUM
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection...
GHSA-5jrx-957p-3f93
MEDIUM
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site...
GHSA-4v8f-3c7h-9xrw
HIGH
An OS command injection vulnerability exists in the VPN module of TP-Link AXE75 V1 routers. This...
GHSA-jhhh-39pj-vgq6
UNKNOWN
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management...
GHSA-j56f-72j5-v78h
UNKNOWN
A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150...
GHSA-w7m2-6chv-wg69
HIGH
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary...
GHSA-4pg7-2q5x-32w4
UNKNOWN
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows...