Export limit exceeded: 401333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 401333 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (1 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-91078 | 1 Wordpress-extensions | 1 Tillkit | 2026-10-04 | 8.2 High |
| The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal data and modify store data. | ||||
Page 1 of 1.