Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Fraudless

#20579of 56,326
13.7Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-68373
7.2
2026-08-06
WordPress · Fluentsmtp · CVE-2026-16636
**Name of the Vulnerable Software and Affected Versions** FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider versions prior to 2.2.96 **Description** Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. The issue occurs in the Email Logs detail view when an administrator uses the Prev/Next navigation controls, as this specific path bypasses the `escapeHtml` pipeline. The malicious payload is delivered through the `to.name` variable within a `wp mail()` function call. **Recommendations** Update FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider to version 2.2.96 or later.
PT-2026-52783
6.5
2026-06-26
Getgenie · Getgenie · CVE-2026-57316
**Name of the Vulnerable Software and Affected Versions** GetGenie versions prior to 4.4.3 **Description** An issue exists that leads to the exposure of sensitive subscriber data. **Recommendations** Update to a version newer than 4.4.2.