Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Ritsuy

#20699de 56,333
13.6CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2026-50322
7.1
2026-04-21
WordPress · Collectchat · CVE-2026-40765
**Nome do Software Vulnerável e Versões Afetadas** collectchat versões anteriores a 2.5.0 **Description** O plugin Chatbot for WordPress by Collect.chat está sujeito a Stored Cross-Site Scripting (XSS), uma falha onde scripts maliciosos são armazenados permanentemente no servidor alvo. Isso ocorre devido à sanitização insuficiente de entrada e escape insuficiente de saída, permitindo que atacantes não autenticados injetem scripts web arbitrários em páginas. Esses scripts são executados automaticamente sempre que um usuário visita a página afetada. **Recommendations** Atualize o plugin para uma versão posterior à 2.4.9.
PT-2025-39062
6.5
2025-09-22
WordPress · Make Column Clickable Elementor · CVE-2025-59592
**Name of the Vulnerable Software and Affected Versions** Make Column Clickable Elementor versions through 1.6.0 **Description** The software contains a flaw related to improper handling of user-supplied data when creating web pages, potentially leading to Cross-site Scripting (XSS). This allows for the injection of malicious scripts into web pages viewed by other users. The issue is a Stored XSS, meaning the malicious script is permanently stored on the target server. **Recommendations** Update Make Column Clickable Elementor to a version later than 1.6.0.