Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Search: ajax.php

Search Results: "ajax.php"

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-11911: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in eemitch Simple File ListCVE-2026-11911
0

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The simplefilelist_edit_job AJAX action is registered via wp_ajax_nopriv_, making it accessible without authentication, and the is_admin() guard that would otherwise restrict access is bypassed because is_admin() always returns true for requests to the admin-ajax.php endpoint.

Join the discussion
CVE-2026-11603: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in brthumar1959 Product Filter Widget for ElementorCVE-2026-11603
0

The Product Filter Widget for Elementor WordPress plugin up to version 1.0.6 is vulnerable to reflected Cross-Site Scripting (XSS) via the 'args[filterFormArray]' parameter. This vulnerability arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts. Exploitation requires tricking a user into visiting a malicious page that triggers a CSRF-style form auto-submission to the admin-ajax.php endpoint, which lacks nonce verification or capability checks.

Join the discussion
CVE-2026-10737: CWE-862 Missing Authorization in smartypants SP Project & Document ManagerCVE-2026-10737
0

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. This makes it possible for unauthenticated attackers to read file metadata and obtain download links for arbitrary files stored inside project folders on the server, which can contain sensitive information. The authorization gate uses a negated nonce check OR-chained with permission checks, meaning a missing or invalid nonce causes the entire condition to evaluate to true and bypass all preceding capability and ownership checks. The secondary fallback check only denies access for root-level files (pid == 0), leaving all files stored inside project folders fully exposed to unauthenticated users who supply only a valid file ID in a POST request to admin-ajax.php.

Join the discussion
CVE-2026-49491: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Pixastudio Pixa BankCVE-2026-49491
0

Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.

Join the discussion
CVE-2026-10296: SQL Injection in itsourcecode Fees Management SystemCVE-2026-10296
0

CVE-2026-10296 is a medium severity SQL injection vulnerability in itsourcecode Fees Management System version 1.0. The issue exists in an unknown functionality of the /ajax.php file where manipulation of the Username argument can lead to SQL injection. The vulnerability can be exploited remotely without user interaction and requires low privileges. No official patch or remediation guidance is currently available.

Join the discussion
CVE-2026-10251: SQL Injection in itsourcecode Online House Rental SystemCVE-2026-10251
0

A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

Join the discussion

Showing 1 to 6 of 6 results

Filters:ajax.php
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses