CODEPRESS IT Solutions LLC Visitor Traffic Real Time Statistics Pro
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-57367 affects WP Booking System . WP Booking System. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-27064 affects EverPress Mailster. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-25405 affects DigitalME eRoom. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3.
The CVSS severity warrants an early asset and exposure review.A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.
The CVSS severity warrants an early asset and exposure review.A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
The CVSS severity warrants an early asset and exposure review.Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
The CVSS severity warrants an early asset and exposure review.