Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Thaer Assfour

#23274de 57,684
11.7CVSS total
Vulnerabilidades · 2
Média
2
PT-2026-109495
6.4
2026-10-10
Foliovision · Fv Flowplayer Video Player · CVE-2026-97630
The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Unquoted popup Shortcode Attribute in all versions up to, and including, 7.5.54.7212 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires the profile videos enable bio option to be enabled, as script execution occurs on the author bio/archive page where the profile-video shortcode is rendered.
PT-2026-103852
5.3
2026-10-01
WordPress · Site Reviews · CVE-2026-103340
**Nome do Software Vulnerável e Versões Afetadas** Site Reviews versões anteriores a 8.3.3 **Descrição** Uma falha de autorização ausente no plugin Site Reviews permite a exploração de níveis de segurança de controle de acesso configurados incorretamente. **Recomendações** Atualize o Site Reviews para a versão 8.3.3 ou posterior.