Export limit exceeded: 401333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 401333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 401333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-91078 1 Wordpress-extensions 1 Tillkit 2026-10-04 8.2 High
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data.