Known Vulnerabilities for Allow Php In Posts And Pages by Hitreach
Listed below are 1 of the newest known vulnerabilities associated with "Allow Php In Posts And Pages" by "Hitreach".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-53427 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows s... | Not Provided | 2026-06-29 | 2026-06-29 |
| CVE-2026-35447 json | NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) pro... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-15407 json | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. T... | Not Provided | 2026-07-16 | 2026-07-18 |
| CVE-2026-15286 json | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post ... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-15212 json | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. T... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-13295 json | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in... | Not Provided | 2026-06-27 | 2026-06-29 |
| CVE-2026-13250 json | The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-13010 json | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Inj... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-12738 json | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass i... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-12409 json | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is v... | Not Provided | 2026-07-16 | 2026-07-17 |