codepeople WP Time Slots Booking Form
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48881 affects themetechmount TrueBooker. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48876 affects Web Guy Stop Spammers. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48874 affects Ruben Garcia GamiPress. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48873 affects Montonio Montonio for WooCommerce. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48872 affects WPDeveloper EmbedPress. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.
The CVSS severity warrants an early asset and exposure review.Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
The CVSS severity warrants an early asset and exposure review.Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48838 affects WPExperts Post SMTP. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.CVE-2026-48836 affects MantraBrain Easy Invoice. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.
The CVSS severity warrants an early asset and exposure review.Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
The CVSS severity warrants an early asset and exposure review.OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and prior, the template engine uses a single shared text/template.Template instance (tpl package-level variable in service/internal/tpl/templates.go) across all goroutines. Every action execution calls tpl.Parse(source) followed by t.Execute() on this shared instance with no synchronization. When two or more actions execute concurrently (which is the normal case — each ExecRequest spawns a goroutine), a race condition occurs: one goroutine's Parse overwrites the template tree while another goroutin...
The CVSS severity warrants an early asset and exposure review.Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from .claude/settings.local.json without dedicated user approval. A malicious workspace or agent-created file could configure hooks that run local commands in the user's context when an agent turn ends. This could allow sandbox escape, persistence across turns, local data access, or follow-on compromise. This issue has been fixed in version 3.0.0.
The CVSS severity warrants an early asset and exposure review.Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configuration scenarios. This affects both the WebMVC and WebFlux Gateway Servers. Affected versions: Spring Cloud Gateway 3.1.x (fix 3.1.13). Spring Cloud Gateway 4.1.x (fix 4.1.13). Spring Cloud Gateway 4.2.x (fix 4.2.9). Spring Cloud Gateway 4.3.x (fix 4.3.5). Spring Cloud Gateway 5.0.x (fix 5.0.2).
The CVSS severity warrants an early asset and exposure review.