Vulnerabilities

Summary — last 7 days

New vulnerabilities2,699▼ 343 vs. last week
Critical / high1,270▼ 197 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)208▼ 123 vs. last week
–

34 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (4.4)0.34%—Print PDF Email BY PrintfriendlyAI7/11/20267/13/2026
The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
DeferredMedium (6.5)0.22%—Vladimir Prelovac SEO Friendly ImagesAI4/8/20267/24/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image allows DOM-Based XSS.This issue affects SEO Friendly Images: from n/a through <= 3.0.5.
DeferredMedium (4.3)0.18%💥 PoCFriendly Functions FOR WelcartAI1/24/20266/17/2026
The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the settings page. This makes it possible for unauthenticated attackers to update plugin settings via a forged request…
DeferredMedium (6.5)0.21%—Itayxd Responsive-mobile-friendly-tooltipAI8/28/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ItayXD Responsive Mobile-Friendly Tooltip responsive-mobile-friendly-tooltip allows Stored XSS.This issue affects Responsive Mobile-Friendly Tooltip: from n/a through <= 1.6.6.
DeferredMedium (6.1)0.28%—Friendly Functions FOR WelcartAI11/21/20246/17/2026
The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to inject malicious web scripts via a…
DeferredMedium (4.8)0.41%—Usvn User-friendly SVNAI9/20/20246/17/2026
Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and "siteLogo".
DeferredMedium (5.3)0.55%—Friendlycaptcha OfficialAITypo3AITypo3 FormAI6/21/20246/17/2026
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the…
AnalyzedMedium (4.4)0.18%—Friendlyelec Friendlywrt3/15/20246/17/2026
Cryptographic key vulnerability encoded in the FriendlyWrt firmware affecting version 2022-11-16.51b3d35. This vulnerability could allow an attacker to compromise the confidentiality and integrity of encrypted data.
ModifiedMedium (4.8)0.39%—Print, Pdf, Email BY Printfriendly10/25/20236/17/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Print, PDF, Email by PrintFriendly plugin <= 5.5.1 versions.
ModifiedMedium (4.8)0.37%—Bajorat-media PB SEO Friendly Images5/4/20236/17/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PB SEO Friendly Images plugin <= 4.0.5 versions.
ModifiedMedium (6.1)0.58%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System3/15/20236/17/2026
A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file cashconfirm.php of the component POST Parameter Handler. The manipulation of the argument transactioncode leads to cross…
ModifiedCritical (9.8)0.76%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System3/15/20236/17/2026
A vulnerability was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file addmem.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to sql injection. The attack may…
ModifiedCritical (9.8)0.74%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System3/13/20236/17/2026
A vulnerability classified as critical was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This vulnerability affects unknown code of the file paypalsuccess.php of the component POST Parameter Handler. The manipulation of the argument cusid leads to sql injection. The attack can be…
ModifiedCritical (9.8)0.79%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System3/10/20236/17/2026
A vulnerability, which was classified as critical, was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. This affects an unknown part of the file large.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the…
ModifiedCritical (9.8)0.79%—Friendly Island Pizza Website AND Ordering System Project Friendly Island Pizza Website AND Ordering System3/9/20236/17/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this issue is some unknown functionality of the file deleteorder.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection.…
ModifiedHigh (7.5)0.89%—Wp-print-friendly Project WP Print Friendly1/3/20236/16/2026
A vulnerability classified as problematic has been found in ethitter WP-Print-Friendly up to 0.5.2. This affects an unknown part of the file wp-print-friendly.php. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. Upgrading to version 0.5.3 is able to address this issue.…
ModifiedMedium (4.8)0.59%—Print, Pdf, Email BY Printfriendly6/20/20226/17/2026
The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModifiedMedium (6.1)0.78%—Usvn User-friendly SVN8/5/20206/17/2026
USVN (aka User-friendly SVN) before 1.0.9 allows XSS via SVN logs.
ModifiedCritical (9.8)27%💥 ExploitMobile-friendly-app-builder-by-easytouch Project Mobile-friendly-app-builder-by-easytouch9/14/20176/17/2026
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.
ModifiedMedium (5.4)0.27%—Userfriendlymedia Mills-hazel Property Mgmt10/21/20146/17/2026
The Mills-Hazel Property Mgmt (aka com.appexpress.millshazelpropertymanagement) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedMedium (5.4)0.27%—Userfriendlymedia Joe's Lawn Service10/19/20146/17/2026
The Joe's Lawn Service (aka com.appexpress.joeslawnservice) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModifiedMedium (4.3)1.4%—Usvn User-friendly SVN7/3/20146/17/2026
Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the username field.
ModifiedMedium (6.8)2.1%—Articlefriendly Article Friendly6/2/20106/16/2026
Directory traversal vulnerability in admin/index.php in Article Friendly, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModifiedMedium (4.3)1.2%—Anon-design Printfriendly11/24/20096/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Printfriendly module 6.x before 6.x-1.6 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedHigh (9.3)6.7%💥 ExploitFriendly Technologies Friendly Pppoe Client9/11/20086/16/2026
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.
Orbitaley — Vulnerabilities