CVE-2026-94677High· 7.2▾ TwilightShop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2017-12149Critical· 9.8In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…
CVE-2026-96830High· 7.1Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
CVE-2026-96834Medium· 6.5Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.
CVE-2026-97066Medium· 5.3Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.
CVE-2026-97266Medium· 6.5Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12.1 versions.
CVE-2026-97285Medium· 5.4Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions.