Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Lubin Regnault

#20110de 54,957
13.4CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2026-63575
6.1
2026-07-23
Undefined · Undefined · CVE-2026-9066
The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP Compress WordPress plugin before 7.10.04's loader injects script elements pointing to an attacker-controlled origin, which lets the attacker execute arbitrary JavaScript in the visitor's session on the target site.
PT-2026-50323
7.3
2026-06-17
Dimitri Grassi · Salon Booking System · CVE-2026-40768
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.