87achrafg-stack
5 exploits
Active since May 2026
Avada (Fusion) Builder <= 3.15.2 - Remote Code Execution via PHP Function Injection
WordPress LatePoint plugin <= 5.5.1 - Privilege Escalation vulnerability
CVSS 7.5
Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
CVSS 7.2
Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5
CVSS 9.8
Avada (Fusion) Builder <= 3.15.2 - Remote Code Execution via PHP Function Injection
CVSS 9.8