rootdirective-sec
26 exploits
Active since Jan 2026
WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerability
CVSS 7.1
Langflow < 1.9.2 - Authenticated Insecure Direct Object Reference
CVSS 8.4
FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE
WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
CVSS 9.8
UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc
CVSS 8.1
WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability
CVSS 9.3
SQLAdmin: Authorization Bypass on `ajax_lookup`
CVSS 4.3
Link Whisper Free <= 0.9.0 - Unauthenticated Stored Cross-Site Scripting
CVSS 7.2
Spectra Gutenberg Blocks <= 2.19.25 - Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes
CVSS 8.8
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
CVSS 9.8
Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX
CVSS 7.5
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
CVSS 9.8
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
CVSS 7.3
LMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
CVSS 7.5
Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.6 - Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass
CVSS 8.1
LiteLLM: SQL injection in Proxy API key verification
CVSS 9.8
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
CVSS 8.8
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
CVSS 9.8
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
CVSS 9.8
Wholesale Suite <=2.2.6 - Privilege Escalation
CVSS 7.2
pac4j-jwt <4.5.9/5.7.9/6.3.3 - Auth Bypass
CVSS 9.1
MaxSite CMS <109.1 - Code Injection
CVSS 7.3
wpForo Forum <2.4.14 - SQL Injection
CVSS 7.5
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8