Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Luka Zimonjic

#22180of 56,330
12.1Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-86484
6.8
2026-09-06
Undefined · Undefined · CVE-2026-84028
🚨 CVE-2026-84028 The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page. 🎖@cveNotify
PT-2026-78297
5.3
2026-08-19
Unknown · Truebooker · CVE-2026-18778
**Name of the Vulnerable Software and Affected Versions** TrueBooker versions prior to 1.2.7 **Description** Lack of proper authorization checks in several AJAX actions allows unauthenticated users to retrieve personally identifiable information (PII) of customers who booked appointments. The exposed data includes names, email addresses, phone numbers, and postal addresses. **Recommendations** Update TrueBooker to version 1.2.7 or later.