A vulnerability, which was classified as problematic, has been found in wpcodefactory Cost of Goods Plugin up to 4.1.0 on WordPress. Affected is the function alg_wc_cog_product_cost of the component Shortcode Handler. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-6962. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as problematic was found in AMD Ionic Cloud Driver on Vmware. This impacts an unknown function. Such manipulation leads to untrusted pointer dereference.
This vulnerability is uniquely identified as CVE-2025-62627. Local access is required to approach this attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Fuji Electric Tellus 5.0.2. This affects an unknown function of the component Installation Handler. This manipulation causes exposed dangerous routine.
This vulnerability is handled as CVE-2026-8108. It is possible to launch the attack on the local host. There is not any exploit available.
A vulnerability labeled as problematic has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. Impacted is an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-9989. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as problematic has been detected in techjewel Fluent Forms Plugin up to 6.2.1 on WordPress. This issue affects some unknown processing of the component Conversation Handler. Performing a manipulation of the argument permission_message results in cross site scripting.
This vulnerability is reported as CVE-2026-6828. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in reconurge flowsint up to 1.2.2. This vulnerability affects unknown code. Such manipulation leads to improper access controls.
This vulnerability is documented as CVE-2026-44352. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in warp-tech warpgate up to 0.23.2 on Linux. It has been declared as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument state results in cross-site request forgery.
This vulnerability is cataloged as CVE-2026-44347. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in smub Charitable Plugin up to 1.8.10.4 on WordPress and classified as critical. Affected is the function edit_others_donations. Executing a manipulation of the argument s can lead to sql injection.
This vulnerability is tracked as CVE-2026-7619. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress and classified as critical. This impacts the function create_advertiser of the component AJAX Action Handler. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2025-9988. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in broadstreetads Broadstreet Plugin up to 1.53.1 on WordPress. This affects the function get_sponsored_meta. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2025-9987. It is possible to launch the attack remotely. No exploit is available.