{"schema_version":1,"title":"Xnau Webdesign Participants Database vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 4 vulnerabilities in Xnau Webdesign Participants Database: 0 in the last 7 days and 4 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-11354, was published on 24 July 2026.","url":"https://junglewise.ai/threats/technologies/participants-database","json_url":"https://junglewise.ai/threats/technologies/participants-database.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/participants-database","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":4,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":4},"latest":[{"cve":"CVE-2026-11354","cvss":5.3,"slug":"cve-2026-11354-xnau-participants-database-sensitive-information-exposure-via-id","title":"xnau Participants Database sensitive information exposure via id parameter","severity":"medium","exploited":false,"published_at":"2026-07-24T04:16:51.03+00:00","url":"https://junglewise.ai/threats/cve-2026-11354-xnau-participants-database-sensitive-information-exposure-via-id"},{"cve":"CVE-2026-59555","cvss":10,"slug":"cve-2026-59555-roland-barker-participants-database-arbitrary-file-deletion","title":"Roland Barker Participants Database arbitrary file deletion","severity":"critical","exploited":false,"published_at":"2026-07-23T12:18:33.803+00:00","url":"https://junglewise.ai/threats/cve-2026-59555-roland-barker-participants-database-arbitrary-file-deletion"},{"cve":"CVE-2026-59525","cvss":9.3,"slug":"cve-2026-59525-roland-barker-participants-database-sql-injection","title":"Roland Barker Participants Database SQL injection","severity":"critical","exploited":false,"published_at":"2026-07-23T12:18:32.59+00:00","url":"https://junglewise.ai/threats/cve-2026-59525-roland-barker-participants-database-sql-injection"},{"cve":"CVE-2026-27423","cvss":4.3,"slug":"cve-2026-27423-roland-barker-participants-database-broken-access-control","title":"Roland Barker Participants Database broken access control","severity":"medium","exploited":false,"published_at":"2026-07-23T12:17:18.893+00:00","url":"https://junglewise.ai/threats/cve-2026-27423-roland-barker-participants-database-broken-access-control"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":2,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Xnau Webdesign Participants Database","slug":"participants-database","vendor":{"name":"Xnau Webdesign","slug":"xnau-webdesign","url":"https://junglewise.ai/threats/vendors/xnau-webdesign"},"aliases":[],"category":"library","homepage":"https://xnau.com/work/wordpress-plugins/participants-database/","repo_url":"https://github.com/xnau/participants-database","description":"A WordPress plugin for creating and managing a database of people or items with customizable fields and front-end forms.","url":"https://junglewise.ai/threats/technologies/participants-database"},"most_severe":[{"cve":"CVE-2026-59555","cvss":10,"slug":"cve-2026-59555-roland-barker-participants-database-arbitrary-file-deletion","title":"Roland Barker Participants Database arbitrary file deletion","severity":"critical","exploited":false,"published_at":"2026-07-23T12:18:33.803+00:00","url":"https://junglewise.ai/threats/cve-2026-59555-roland-barker-participants-database-arbitrary-file-deletion"},{"cve":"CVE-2026-59525","cvss":9.3,"slug":"cve-2026-59525-roland-barker-participants-database-sql-injection","title":"Roland Barker Participants Database SQL injection","severity":"critical","exploited":false,"published_at":"2026-07-23T12:18:32.59+00:00","url":"https://junglewise.ai/threats/cve-2026-59525-roland-barker-participants-database-sql-injection"},{"cve":"CVE-2026-11354","cvss":5.3,"slug":"cve-2026-11354-xnau-participants-database-sensitive-information-exposure-via-id","title":"xnau Participants Database sensitive information exposure via id parameter","severity":"medium","exploited":false,"published_at":"2026-07-24T04:16:51.03+00:00","url":"https://junglewise.ai/threats/cve-2026-11354-xnau-participants-database-sensitive-information-exposure-via-id"},{"cve":"CVE-2026-27423","cvss":4.3,"slug":"cve-2026-27423-roland-barker-participants-database-broken-access-control","title":"Roland Barker Participants Database broken access control","severity":"medium","exploited":false,"published_at":"2026-07-23T12:17:18.893+00:00","url":"https://junglewise.ai/threats/cve-2026-27423-roland-barker-participants-database-broken-access-control"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}