A vulnerability identified as problematic has been detected in PayU India Plugin up to 3.8.2 on WordPress. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2024-27193. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Sandi Verdev Watermark RELOADED Plugin up to 1.3.5 on WordPress. It has been classified as problematic. Impacted is an unknown function. Performing a manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2024-27195. The attack can be initiated remotely. There is not any exploit available.
A vulnerability described as critical has been identified in Tourfic Plugin up to 2.11.15 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to unrestricted upload.
This vulnerability is registered as CVE-2024-29135. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as problematic has been found in Themefic Tourfic Plugin up to 2.11.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2024-29137. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as problematic was found in Themefic Tourfic Plugin up to 2.11.17 on WordPress. This affects an unknown part. The manipulation results in deserialization.
This vulnerability is reported as CVE-2024-29136. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as problematic, has been found in DEV Institute Restrict User Access Plugin up to 2.5 on WordPress. This vulnerability affects unknown code. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2024-29138. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as problematic has been discovered in Themefic Tourfic Plugin up to 2.11.8 on WordPress. Affected is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2024-29134. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as problematic was found in Elliot Sowersby Coupon Affiliates Plugin up to 5.12.7 on WordPress. Impacted is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2024-29125. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in Paul Ryley Site Reviews Plugin up to 6.11.6 on WordPress. This issue affects some unknown processing. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2024-29095. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as problematic. The impacted element is an unknown function of the component Loan Plans Handler. Such manipulation of the argument months leads to business logic errors.
This vulnerability is referenced as CVE-2026-30523. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in Bytedance DeerFlow. Affected by this vulnerability is an unknown functionality. This manipulation causes incomplete blacklist.
This vulnerability appears as CVE-2026-34430. The attack may be initiated remotely. There is no available exploit.
It is suggested to install a patch to address this issue.
A vulnerability described as critical has been identified in Volcengine OpenViking up to 0.2.13. Affected by this issue is some unknown functionality of the file /bot/v1/chat. Such manipulation leads to missing authentication.
This vulnerability is traded as CVE-2026-34999. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability identified as problematic has been detected in kingaddons King Addons for Elementor Plugin up to 51.1.53 on WordPress. Affected by this issue is the function esc_attr/esc_url of the component Elementor Widget. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-13535. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability has been found in SourceCodester Pharmacy Product Management System 1.0 and classified as critical. The affected element is an unknown function of the file add-sales.php. This manipulation of the argument txtprice/txttotalcost causes enforcement of behavioral workflow.
The identification of this vulnerability is CVE-2026-30573. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Ora Tools PDF Reader App 4.3.5. It has been classified as critical. This affects an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is identified as CVE-2026-30291. The attack is only possible with local access. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in SourceCodester Zoo Management System 1.0. This affects an unknown function. Such manipulation of the argument msg leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-30526. The attack can be launched remotely. No exploit exists.
A vulnerability was found in DDSN Interactive Acora CMS 10.7.1 and classified as problematic. Affected is an unknown function of the file submit_add_user.asp. Executing a manipulation of the argument First Name/Last Name can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-29598. The attack may be launched remotely. There is no exploit available.