CVE-2026-74008Medium· 5.3▾ SunlitInsertion of Sensitive Information Into Sent Data vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Insertion of Sensitive Information Into Sent Data vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Retrieve Embedded Sensitive Data.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.24.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57737Medium· 6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows DOM-Based XSS.This issue affects Shortcodes and extra fe…
CVE-2025-69016Medium· 4.3Missing Authorization vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for P…
CVE-2026-106501Critical· 9.6Backstage is an open framework for building developer portals
CVE-2026-66666Medium· 6.9Insertion of Sensitive Information Into Sent Data vulnerability in Automattic WordPress allows Retrieve Embedded Sensitive Data. This issue affects WordPress: from 7.1 through 7.1.2, from 7.0 through 7.0.6, from 6.9 through 6.9.9, from …
CVE-2026-105849High· 7.7Payload is a free and open source headless content management system
CVE-2026-39729High· 7.2Unauthenticated Sensitive Data Exposure in Edwiser Bridge <= 4.3.4 versions.