|
CVE-2026-57624
|
|
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
|
Critical
|
リモートコード実行 (RCE)
CWE-94: コードインジェクション
|
2ヶ月前
|
|
CVE-2026-57349
|
|
Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-57623
|
|
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
|
Critical
|
Cwe 1284
|
2ヶ月前
|
|
CVE-2026-57350
|
|
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-57621
|
|
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
|
Critical
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-57355
|
|
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-57361
|
|
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-57354
|
|
Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-57351
|
|
Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-57352
|
|
CVE-2026-57352 の脆弱性 (CVE-2026-57352)
CVE-2026-57352 に 脆弱性 (CVE-2026-57352) が存在。不正な操作・情報露出のリスクがあります。
|
Medium
|
Cwe 1390
|
2ヶ月前
|
|
CVE-2026-57348
|
|
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
|
High
|
SSRF (サーバーサイドリクエストフォージェリ)
Cwe 918
|
2ヶ月前
|
|
CVE-2026-49779
|
|
Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.
Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.
|
Medium
|
パストラバーサル
Cwe 35
|
2ヶ月前
|
|
CVE-2026-57344
|
|
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-39448
|
|
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
|
High
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-42382
|
|
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.
|
High
|
Cwe 98
|
2ヶ月前
|
|
CVE-2026-57345
|
|
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27430
|
|
Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
Unauthenticated Cross Site Scripting (XSS) in TheFox <= 3.9.76 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-56037
|
|
deserialization に 安全でないデシリアライゼーション (CVE-2026-56037)
deserialization に 脆弱性 (CVE-2026-56037) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
High
|
安全でないデシリアライゼーション
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-57347
|
|
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
|
Medium
|
Cwe 201
|
2ヶ月前
|
|
CVE-2026-27419
|
|
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
|
Critical
|
Cwe 434
|
2ヶ月前
|
|
CVE-2026-27414
|
|
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-57343
|
|
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27408
|
|
Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27060
|
|
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
|
High
|
PHP
CWE-502: 安全でないデシリアライゼーション
安全でないデシリアライゼーション
|
2ヶ月前
|
|
CVE-2026-57342
|
|
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
|
Medium
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27426
|
|
CVE-2026-27426 に クロスサイトスクリプティング (CVE-2026-27426)
CVE-2026-27426 に XSS (クロスサイトスクリプティング) (CVE-2026-27426) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27402
|
|
wordpress に クロスサイトスクリプティング (CVE-2026-27402)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-27402) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27436
|
|
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
|
Critical
|
CWE-94: コードインジェクション
|
2ヶ月前
|
|
CVE-2026-27404
|
|
Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27433
|
|
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2026-27425
|
|
Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-27412
|
|
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions.
|
High
|
Cwe 98
|
2ヶ月前
|
|
CVE-2025-69156
|
|
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2025-69155
|
|
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-11946
|
|
CVE-2026-11946 の脆弱性 (CVE-2026-11946)
CVE-2026-11946 に 脆弱性 (CVE-2026-11946) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
Cwe 770
Cwe 789
|
2ヶ月前
|
|
CVE-2025-69154
|
|
wordpress に クロスサイトスクリプティング (CVE-2025-69154)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2025-69154) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2025-69153
|
|
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2026-14449
|
|
CVE-2026-14449 に クロスサイトスクリプティング (CVE-2026-14449)
CVE-2026-14449 に XSS (クロスサイトスクリプティング) (CVE-2026-14449) が存在。不正な操作・情報露出のリスクがあります。
|
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2025-69133
|
|
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
|
High
|
Cwe 98
|
2ヶ月前
|
|
CVE-2025-69134
|
|
wordpress の脆弱性 (CVE-2025-69134)
wordpress に 脆弱性 (CVE-2025-69134) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
WordPress
Cwe 862
|
2ヶ月前
|
|
CVE-2025-66076
|
|
Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
|
Medium
|
Cwe 862
|
2ヶ月前
|
|
CVE-2025-69094
|
|
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
|
High
|
SQLインジェクション
CWE-89: SQLインジェクション
|
2ヶ月前
|
|
CVE-2025-69132
|
|
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
|
Medium
|
Cwe 201
|
2ヶ月前
|
|
CVE-2025-69152
|
|
wordpress に クロスサイトスクリプティング (CVE-2025-69152)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2025-69152) が存在。不正な操作・情報露出のリスクがあります。
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2ヶ月前
|
|
CVE-2025-58902
|
|
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
|
High
|
Cwe 98
|
2ヶ月前
|
|
ROOT-APP-MAVEN-CVE-2026-40992
|
|
io.root.org.springframework.boot:spring-boot-autoconfigure の脆弱性 (ROOT-APP-MAVEN-CVE-2026-40992)
io.root.org.springframework.boot:spring-boot-autoconfigure に 脆弱性 (ROOT-APP-MAVEN-CVE-2026-40992) が存在。不正な操作・情報露出のリスクがあります。対策: `3.5.3-root.io.3, 4.0.6-root.io.1` 以上に更新。
|
|
|
2ヶ月前
|
|
ROOT-APP-MAVEN-CVE-2026-41001
|
|
io.root.org.springframework.boot:spring-boot の脆弱性 (ROOT-APP-MAVEN-CVE-2026-41001)
io.root.org.springframework.boot:spring-boot に 脆弱性 (ROOT-APP-MAVEN-CVE-2026-41001) が存在。不正な操作・情報露出のリスクがあります。対策: `3.5.3-root.io.1, 3.5.3-root.io.2, 3.5.3-root.io.3, 4.0.6-root.io.1` 以上に更新。
|
|
|
2ヶ月前
|
|
ROOT-APP-GOBINARY-CVE-2026-53489
|
|
rootio-github.com/containerd/containerd/v2 の脆弱性 (ROOT-APP-GOBINARY-CVE-2026-53489)
rootio-github.com/containerd/containerd/v2 に 脆弱性 (ROOT-APP-GOBINARY-CVE-2026-53489) が存在。不正な操作・情報露出のリスクがあります。対策: `v2.2.4-root.io.1` 以上に更新。
|
|
|
2ヶ月前
|
|
ROOT-APP-GOBINARY-CVE-2026-53488
|
|
rootio-github.com/containerd/containerd/v2 の脆弱性 (ROOT-APP-GOBINARY-CVE-2026-53488)
rootio-github.com/containerd/containerd/v2 に 脆弱性 (ROOT-APP-GOBINARY-CVE-2026-53488) が存在。不正な操作・情報露出のリスクがあります。対策: `v2.2.4-root.io.1` 以上に更新。
|
|
|
2ヶ月前
|
|
ROOT-APP-GOBINARY-CVE-2026-53492
|
|
rootio-github.com/containerd/containerd/v2 の脆弱性 (ROOT-APP-GOBINARY-CVE-2026-53492)
rootio-github.com/containerd/containerd/v2 に 脆弱性 (ROOT-APP-GOBINARY-CVE-2026-53492) が存在。不正な操作・情報露出のリスクがあります。対策: `v2.2.4-root.io.1` 以上に更新。
|
|
|
2ヶ月前
|