Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2026-78362
- EPSS 0.15%
- Veröffentlicht 05.09.2026 06:00:05
- Zuletzt bearbeitet 08.09.2026 19:09:21
The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress p...
7.5
CVE-2025-15285
- EPSS 0.4%
- Veröffentlicht 04.02.2026 08:25:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and including, 2....
6.1
CVE-2025-48146
- EPSS 0.13%
- Veröffentlicht 16.05.2025 15:45:16
- Zuletzt bearbeitet 23.04.2026 15:30:53
Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline lupsonline-link-netwerk allows Stored XSS.This issue affects SEO Flow by LupsOnline: from n/a through <= 2.2.1.
1