Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-09 CVE-2024-13440 Unspecified vulnerability in Superstorefinder Super Store Finder
The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
superstorefinder
8.2
2025-02-08 CVE-2025-0169 Cross-site Scripting vulnerability in Scriptsbundle DWT Listing
The DWT - Directory & Listing WordPress Theme is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
scriptsbundle CWE-79
5.4
2025-02-08 CVE-2025-0316 The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5.
network
low complexity
CWE-288
critical
9.8
2025-02-08 CVE-2024-54176 IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 and IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14 and 7.3 through 7.3.2 could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
network
low complexity
CWE-306
4.3
2025-02-08 CVE-2024-13850 Cross-site Scripting vulnerability in Mijnpress Simple ADD Pages or Posts
The Simple add pages or posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping.
network
low complexity
mijnpress CWE-79
4.8
2025-02-08 CVE-2025-1117 A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart.
network
low complexity
CWE-74
7.3
2025-02-08 CVE-2025-1116 A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on OpenCart.
network
low complexity
CWE-74
7.3
2025-02-07 CVE-2025-25187 Unspecified vulnerability in Joplin Project Joplin
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks.
network
low complexity
joplin-project
5.4
2025-02-07 CVE-2025-1106 Path Traversal vulnerability in Cmseasy 7.7.7.9
A vulnerability classified as critical has been found in CmsEasy 7.7.7.9.
network
low complexity
cmseasy CWE-22
6.5
2025-02-07 CVE-2025-1105 A vulnerability was found in SiberianCMS 4.20.6.
network
low complexity
CWE-94
4.3