Vulnerabilities

Summary — last 7 days

New vulnerabilities2,702▼ 361 vs. last week
Critical / high1,278▼ 199 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)216▼ 113 vs. last week
–

56 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.9)0.19%—Nextscripts Social Networks Auto PosterAI9/27/20269/28/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,…
DeferredHigh (7.1)0.25%—Nextscripts Social Networks Auto PosterAI8/19/20268/26/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a…
DeferredHigh (8.2)0.66%—Ossn Open Source Social NetworkAI4/24/20266/17/2026
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file size on disk may be…
DeferredLow (2.1)0.32%—Code-projects Social Networking SiteAI3/27/20266/17/2026
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and…
DeferredLow (2)0.33%—Code-projects Social Networking SiteAI3/27/20266/17/2026
A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly…
DeferredMedium (6.4)0.34%💥 PoCNextscripts Social Networks Auto PosterAI3/10/20266/17/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[nxs_fbembed]` shortcode in all versions up to, and including, 4.4.6. This is due to insufficient input sanitization and output escaping on the `snapFB` post meta value. This makes it possible for…
DeferredHigh (8.8)0.58%—Nextscripts Social-networks-auto-poster-facebook-twitter-gAI3/5/20266/17/2026
Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
AnalyzedMedium (5.5)0.38%—Code-projects Social Networking Site2/7/20266/17/2026
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be…
AnalyzedLow (2.1)0.35%—Fabian Nero Social Networking Site11/17/202510/7/2026
A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AnalyzedMedium (5.5)0.44%—Fabian Nero Social Networking Site11/17/202510/7/2026
A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AnalyzedMedium (6.5)0.21%💥 PoCOpensource-socialnetwork Open Source Social Network11/5/20256/17/2026
OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter.
AnalyzedHigh (7.3)0.29%💥 PoCOpensource-socialnetwork Open Source Social Network11/3/20256/17/2026
Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends.
AnalyzedMedium (5.5)0.48%—Fabian Nero Social Networking Site10/27/202510/8/2026
A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the file /friendprofile.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be…
AnalyzedMedium (5.5)0.48%—Fabian Nero Social Networking Site10/27/202510/8/2026
A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of the argument message_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalyzedMedium (5.5)0.48%—Fabian Nero Social Networking Site10/27/202510/8/2026
A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an unknown functionality of the file /addfriend.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be…
AnalyzedMedium (5.5)0.48%—Fabian Nero Social Networking Site10/27/202510/8/2026
A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the file /acceptoffres.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
DeferredLow (2.1)0.25%—Ipynch Social Network WebsiteAI10/11/202510/8/2026
A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The affected element is an unknown function of the component Search. Performing manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to…
AnalyzedMedium (6.9)0.63%—Fabian Nero Social Networking Site5/4/20256/17/2026
A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This affects an unknown part of the file /index.php. The manipulation of the argument fname/lname/login/password2/cpassword/address/cnumber/email/gender/propic/month leads to sql injection. It is possible to…
DeferredHigh (7.1)0.26%—Lemonadestudio Lemonade Social Networks Autoposter PinterestAI1/2/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0.
AnalyzedMedium (6.5)0.50%—Nextscripts Social Networks Auto Poster10/16/20246/17/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on multiple user privilege/security functions provided in versions up to, and including 4.3.17. This makes it possible for low-privileged attackers, like subscribers, to perform…
ModifiedMedium (6.1)0.31%—Nextscripts Social Networks Auto Poster7/22/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows DOM-Based XSS.This issue affects NextScripts: from n/a through <= 4.4.7.
ModifiedMedium (6.5)0.34%—Nextscripts Social Networks Auto Poster5/22/20246/17/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including…
ModifiedMedium (6.1)0.39%—Nextscripts Social Networks Auto Poster5/22/20246/17/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
ModifiedMedium (4.3)0.18%—Nextscripts Social Networks Auto Poster5/22/20246/17/2026
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated attackers to delete arbitrary posts or…
ModifiedMedium (5.4)0.45%—Code-projects Social Networking Site1/19/20246/17/2026
A vulnerability was found in code-projects Social Networking Site 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file message.php of the component Message Page. The manipulation of the argument Story leads to cross site scripting. The attack may be launched remotely. The…
Orbitaley — Vulnerabilities