Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Koutrouss Naddara

#21123of 56,330
13.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-52426
7.1
2026-06-25
H5P · H5P · CVE-2026-56006
**Name of the Vulnerable Software and Affected Versions** H5P versions prior to 1.17.7 **Description** An unauthenticated Cross Site Scripting (XSS) issue exists, allowing an attacker to execute malicious scripts in the browser of a user without requiring authentication. **Recommendations** Update to a version newer than 1.17.6.
PT-2024-11503
6.1
2024-01-16
WordPress · The Super Forms - Drag & Drop Form Builder · CVE-2022-0402
**Name of the Vulnerable Software and Affected Versions** The Super Forms - Drag & Drop Form Builder WordPress plugin versions prior to 6.0.4 **Description** The issue is related to a Reflected Cross-Site Scripting problem. The `bob czy panstwa sprawa zostala rozwiazana` parameter is not properly escaped before being outputted in an attribute via the "super language switcher" AJAX action. This action also lacks CSRF protection, making it easier for attackers to target any user. **Recommendations** For versions prior to 6.0.4, update to version 6.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the "super language switcher" AJAX action until a patch is applied. Avoid using the `bob czy panstwa sprawa zostala rozwiazana` parameter in the affected AJAX endpoint until the issue is resolved.