E-Shot
Forfront · 2 CVEs
CVE-2026-3642
MEDIUM
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX
Apr 15, 2026
CVE-2026-3546
MEDIUM
e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via…
Mar 21, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-3642 | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX | MEDIUM | 0.39% | Apr 15, 2026 |
| CVE-2026-3546 | e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' A… | MEDIUM | 0.40% | Mar 21, 2026 |
Showing 1 to 2 of 2 CVEs