Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-02-23 CVE-2025-1579 Code Injection vulnerability in Code-Projects Blood Bank System 1.0
A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic.
network
low complexity
code-projects CWE-94
6.1
2025-02-23 CVE-2025-1578 Injection vulnerability in PHPgurukul Online Shopping Portal 2.1
A vulnerability, which was classified as critical, was found in PHPGurukul Online Shopping Portal 2.1.
network
low complexity
phpgurukul CWE-74
7.5
2025-02-23 CVE-2025-1577 Code Injection vulnerability in Code-Projects Blood Bank System 1.0
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0.
network
low complexity
code-projects CWE-94
5.4
2025-02-23 CVE-2024-13728 The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2025-02-23 CVE-2025-1576 Injection vulnerability in Fabianros Real Estate Property Management System 1.0
A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0.
network
low complexity
fabianros CWE-74
critical
9.8
2025-02-23 CVE-2025-1575 A vulnerability classified as problematic has been found in Harpia DiagSystem 12.
network
low complexity
CWE-99
4.3
2025-02-22 CVE-2025-0957 The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
7.2
2025-02-22 CVE-2025-0918 The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2025-02-22 CVE-2025-0953 The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2025-02-22 CVE-2025-1556 A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0.
network
low complexity
CWE-502
4.7