Weekly Vulnerabilities Reports > February 17 to 23, 2025

Overview

287 new vulnerabilities reported during this period, including 38 critical vulnerabilities and 61 high severity vulnerabilities. This weekly summary report vulnerabilities in 153 products from 138 vendors including Wegia, Eniture, IBM, Churchcrm, and Tenda. Vulnerabilities are notably categorized as "Cross-site Scripting", "SQL Injection", "Cross-Site Request Forgery (CSRF)", "Code Injection", and "Missing Authorization".

  • 267 reported vulnerabilities are remotely exploitables.
  • 161 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 139 reported vulnerabilities are exploitable by an anonymous user.
  • Wegia has the most reported vulnerabilities, with 13 reported vulnerabilities.
  • Wegia has the most reported critical vulnerabilities, with 10 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

38 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-02-23 CVE-2025-1596 Mayurik Injection vulnerability in Mayurik Best Church Management Software 1.0

A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical.

9.8
2025-02-23 CVE-2025-1593 Mayurik Unrestricted Upload of File with Dangerous Type vulnerability in Mayurik Best Employee Management System 1.0

A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0.

9.8
2025-02-23 CVE-2025-1582 Phpgurukul Injection vulnerability in PHPgurukul Online Nurse Hiring System 1.0

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0.

9.8
2025-02-23 CVE-2025-1583 Phpgurukul Injection vulnerability in PHPgurukul Online Nurse Hiring System 1.0

A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0.

9.8
2025-02-23 CVE-2025-1581 Phpgurukul Injection vulnerability in PHPgurukul Online Nurse Hiring System 1.0

A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0.

9.8
2025-02-23 CVE-2025-1576 Fabianros Injection vulnerability in Fabianros Real Estate Property Management System 1.0

A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0.

9.8
2025-02-22 CVE-2025-1509 Wpguru Code Injection vulnerability in Wpguru Show ME the Cookies 1.0

The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.

9.8
2025-02-22 CVE-2025-1510 Keesiemeijer Code Injection vulnerability in Keesiemeijer Custom Post Type Date Archives

The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1.

9.8
2025-02-21 CVE-2025-1539 Dlink Out-of-bounds Write vulnerability in Dlink Dap-1320 Firmware 1.0

A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00.

9.8
2025-02-20 CVE-2025-25663 Tenda Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06

A vulnerability was found in Tenda AC8V4 V16.03.34.06.

9.8
2025-02-20 CVE-2025-25664 Tenda Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.

9.8
2025-02-20 CVE-2025-25667 Tenda Classic Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.

9.8
2025-02-20 CVE-2025-25668 Tenda Classic Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06

Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.

9.8
2025-02-20 CVE-2025-25674 Tenda Classic Buffer Overflow vulnerability in Tenda Ac10 Firmware 15.03.06.23

Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.

9.8
2025-02-20 CVE-2025-25675 Tenda Command Injection vulnerability in Tenda Ac10 Firmware 15.03.06.23

Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function.

9.8
2025-02-20 CVE-2025-27096 Wegia SQL Injection vulnerability in Wegia 3.2.13

WeGIA is a Web Manager for Institutions with a focus on Portuguese language.

9.8
2025-02-20 CVE-2024-13789 Matiskiba Deserialization of Untrusted Data vulnerability in Matiskiba Ravpage

The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted input from the 'paramsv2' parameter.

9.8
2025-02-20 CVE-2024-13792 EX Themes Code Injection vulnerability in Ex-Themes Woocommerce Food

The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2.

9.8
2025-02-19 CVE-2025-21355 Microsoft Missing Authentication for Critical Function vulnerability in Microsoft Bing

Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network

9.8
2025-02-19 CVE-2025-24989 Microsoft Unspecified vulnerability in Microsoft Power Pages

An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified.

9.8
2025-02-18 CVE-2025-26606 Wegia Improper Access Control vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26607 Wegia Improper Access Control vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26608 Wegia Improper Access Control vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26609 Wegia Improper Access Control vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26610 Wegia SQL Injection vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26611 Wegia Improper Access Control vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26612 Wegia SQL Injection vulnerability in Wegia

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26613 Wegia Improper Access Control vulnerability in Wegia 3.2.13

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2025-26617 Wegia Improper Access Control vulnerability in Wegia 3.2.13

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

9.8
2025-02-18 CVE-2024-13797 Presslayouts Code Injection vulnerability in Presslayouts Pressmart

The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16.

9.8
2025-02-18 CVE-2025-1023 Churchcrm SQL Injection vulnerability in Churchcrm

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality.

9.8
2025-02-18 CVE-2024-12860 Carspot Project Unspecified vulnerability in Carspot Project Carspot

The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3.

9.8
2025-02-18 CVE-2024-13556 Wecantrack Deserialization of Untrusted Data vulnerability in Wecantrack Affiliate Links

The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export.

9.8
2025-02-18 CVE-2024-13725 Keap Path Traversal vulnerability in Keap Official OPT in Forms

The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter.

9.8
2025-02-17 CVE-2025-1379 Code Projects SQL Injection vulnerability in Code-Projects Real Estate Property Management System 1.0

A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical.

9.8
2025-02-17 CVE-2025-1380 Codezips SQL Injection vulnerability in Codezips GYM Management System 1.0

A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical.

9.8
2025-02-17 CVE-2025-1387 Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
9.8
2025-02-23 CVE-2025-1588 Phpgurukul Path Traversal: '../filedir' vulnerability in PHPgurukul Online Nurse Hiring System 1.0

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical.

9.1

61 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-02-21 CVE-2025-1538 Dlink Out-of-bounds Write vulnerability in Dlink Dap-1320 Firmware 1.0

A vulnerability classified as critical was found in D-Link DAP-1320 1.00.

8.8
2025-02-21 CVE-2024-13353 Cyberchimps Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cyberchimps Responsive Addons for Elementor

The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via several widgets.

8.8
2025-02-20 CVE-2024-49779 IBM Cross-Site Request Forgery (CSRF) vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies.

8.8
2025-02-20 CVE-2024-13753 Webcodingplace Cross-Site Request Forgery (CSRF) vulnerability in Webcodingplace Ultimate Classified Listings

The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.

8.8
2025-02-19 CVE-2024-28777 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization.
8.8
2025-02-19 CVE-2024-52902 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system.
8.8
2025-02-19 CVE-2025-1132 Churchcrm SQL Injection vulnerability in Churchcrm

A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter.

8.8
2025-02-19 CVE-2025-1441 Royal Elementor Addons Cross-Site Request Forgery (CSRF) vulnerability in Royal-Elementor-Addons Royal Elementor Addons

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007.

8.8
2025-02-18 CVE-2025-26614 Wegia SQL Injection vulnerability in Wegia 3.2.13

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

8.8
2025-02-18 CVE-2024-13636 Unitedthemes Deserialization of Untrusted Data vulnerability in Unitedthemes Brooklyn 4.9.7.6

The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.9.2 via deserialization of untrusted input in the ot_decode function.

8.8
2025-02-18 CVE-2024-13369 Goodlayers SQL Injection vulnerability in Goodlayers Tour Master

The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

8.8
2025-02-18 CVE-2024-13315 Shopwarden Cross-Site Request Forgery (CSRF) vulnerability in Shopwarden

The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11.

8.8
2025-02-18 CVE-2024-13677 Istmoplugins Missing Authorization vulnerability in Istmoplugins GET Bookings WP

The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.27.

8.8
2025-02-18 CVE-2024-13852 Backie Cross-Site Request Forgery (CSRF) vulnerability in Backie Option Editor

The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0.

8.8
2025-02-17 CVE-2025-1389 Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
8.8
2025-02-17 CVE-2025-1388 Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells
8.8
2025-02-20 CVE-2024-49782 IBM Improper Validation of Certificate with Host Mismatch vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0  could allow a remote attacker to spoof mail server identity when using SSL/TLS security.

8.2
2025-02-19 CVE-2023-47160 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
8.2
2025-02-18 CVE-2024-13684 Smartzminds Cross-Site Request Forgery (CSRF) vulnerability in Smartzminds Reset

The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.

8.1
2025-02-19 CVE-2024-45084 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection.
8.0
2025-02-21 CVE-2025-1471 Eclipse Unspecified vulnerability in Eclipse OMR

In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion.

7.8
2025-02-23 CVE-2025-1578 Phpgurukul Injection vulnerability in PHPgurukul Online Shopping Portal 2.1

A vulnerability, which was classified as critical, was found in PHPGurukul Online Shopping Portal 2.1.

7.5
2025-02-22 CVE-2024-13474 The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
7.5
2025-02-21 CVE-2024-11260 Pixelite SQL Injection vulnerability in Pixelite Events Manager

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-21 CVE-2024-13818 Genetechsolutions Information Exposure Through Log Files vulnerability in Genetechsolutions PIE Register

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3.9 through publicly exposed log files.

7.5
2025-02-20 CVE-2025-27097 THE Guild Resource Exhaustion vulnerability in The-Guild Graphql Mesh

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL.

7.5
2025-02-20 CVE-2025-27098 THE Guild Path Traversal vulnerability in The-Guild Graphql Mesh CLI and Graphql Mesh Http

GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL.

7.5
2025-02-20 CVE-2025-27091 Cisco Heap-based Buffer Overflow vulnerability in Cisco Openh264

OpenH264 is a free license codec library which supports H.264 encoding and decoding.

7.5
2025-02-20 CVE-2024-13476 Eniture SQL Injection vulnerability in Eniture LTL Freight Quotes

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_dropship' AJAX endpoint in all versions up to, and including, 2.3.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2025-27092 CMU Path Traversal vulnerability in CMU Ghosts

GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise.

7.5
2025-02-19 CVE-2024-13478 Eniture SQL Injection vulnerability in Eniture LTL Freight Quotes

The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13479 Eniture SQL Injection vulnerability in Eniture LTL Freight Quotes

The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13481 The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
7.5
2025-02-19 CVE-2024-13483 Eniture SQL Injection vulnerability in Eniture LTL Freight Quotes

The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13485 Eniture SQL Injection vulnerability in Eniture LTL Freight Quotes

The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13491 Eniture SQL Injection vulnerability in Eniture Small Package Quotes

The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13533 Eniture SQL Injection vulnerability in Eniture Small Package Quotes

The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13534 Eniture SQL Injection vulnerability in Eniture Small Package Quotes

The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13489 Eniture SQL Injection vulnerability in Eniture LTL Freight Quotes

The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

7.5
2025-02-19 CVE-2024-13468 The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9.
7.5
2025-02-19 CVE-2024-13592 The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'team-builder-vc' shortcode.
7.5
2025-02-18 CVE-2025-27113 Xmlsoft Unspecified vulnerability in Xmlsoft Libxml2

libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c.

7.5
2025-02-18 CVE-2025-26615 Wegia Improper Access Control vulnerability in Wegia 3.2.13

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

7.5
2025-02-18 CVE-2025-26616 Wegia Improper Access Control vulnerability in Wegia 3.2.13

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.

7.5
2025-02-18 CVE-2024-13681 Undsgn Unspecified vulnerability in Undsgn Uncode

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6.

7.5
2025-02-18 CVE-2024-13622 Imaginate Solutions Unspecified vulnerability in Imaginate-Solutions File Uploads Addon for Woocommerce

The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the 'uploads' directory.

7.5
2025-02-17 CVE-2025-1374 Fabianros SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0

A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0.

7.5
2025-02-21 CVE-2025-1536 A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208.
7.3
2025-02-21 CVE-2025-1535 A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161.
7.3
2025-02-19 CVE-2025-1464 A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204.
7.3
2025-02-19 CVE-2025-1448 A vulnerability was found in Synway SMG Gateway Management Software up to 20250204.
7.3
2025-02-23 CVE-2025-1590 Janobe Unrestricted Upload of File with Dangerous Type vulnerability in Janobe E-Learning System 1.0

A vulnerability was found in SourceCodester E-Learning System 1.0.

7.2
2025-02-22 CVE-2025-0957 The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping.
7.2
2025-02-22 CVE-2024-13899 Misterpah Deserialization of Untrusted Data vulnerability in Misterpah Mambo Joomla Importer 1.0

The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function.

7.2
2025-02-21 CVE-2024-13900 Satollo Code Injection vulnerability in Satollo Head, Footer, and Post Injections

The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0.

7.2
2025-02-19 CVE-2025-1133 Churchcrm SQL Injection vulnerability in Churchcrm

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality.

7.2
2025-02-19 CVE-2025-1134 Churchcrm SQL Injection vulnerability in Churchcrm

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality.

7.2
2025-02-19 CVE-2025-1135 Churchcrm SQL Injection vulnerability in Churchcrm

A vulnerability exists in ChurchCRM 5.13.0.

7.2
2025-02-19 CVE-2024-11582 The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping.
7.2
2025-02-17 CVE-2025-0924 The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping.
7.2
2025-02-20 CVE-2024-49781 IBM XXE vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data.

7.1

180 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-02-18 CVE-2025-26465 Openbsd
Debian
Redhat
Netapp
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled.
6.8
2025-02-19 CVE-2024-45777 A flaw was found in grub2.
6.7
2025-02-18 CVE-2024-45776 When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer.
6.7
2025-02-19 CVE-2025-1465 Lmxcms Code Injection vulnerability in Lmxcms 1.41

A vulnerability, which was classified as problematic, was found in lmxcms 1.41.

6.6
2025-02-21 CVE-2024-13713 Wpexperts SQL Injection vulnerability in Wpexperts Givewp Square

The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-02-21 CVE-2024-12276 Ultimatemember SQL Injection vulnerability in Ultimatemember Ultimate Member

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-02-21 CVE-2024-13235 Pinpoint SQL Injection vulnerability in Pinpoint Booking System

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-02-20 CVE-2025-0866 Legoeso SQL Injection vulnerability in Legoeso PDF Manager

The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-02-20 CVE-2024-49355 IBM Improper Output Neutralization for Logs vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature.

6.5
2025-02-20 CVE-2024-49780 IBM Unspecified vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system.

6.5
2025-02-19 CVE-2024-45081 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks.
6.5
2025-02-19 CVE-2024-13676 The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
6.5
2025-02-19 CVE-2025-0865 DE Baat Cross-Site Request Forgery (CSRF) vulnerability in De-Baat WP Media Category Management

The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3.

6.5
2025-02-18 CVE-2024-13691 Undsgn Unspecified vulnerability in Undsgn Uncode

The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6.

6.5
2025-02-18 CVE-2024-13595 Modalsurvey SQL Injection vulnerability in Modalsurvey Simple Signup Form

The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

6.5
2025-02-20 CVE-2025-1043 The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode.
6.4
2025-02-19 CVE-2025-0677 A flaw was found in grub2.
6.4
2025-02-19 CVE-2024-11335 The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-11753 The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-11778 The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-12522 The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13390 The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13462 The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13589 The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13591 The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13657 The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, 20200131 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13660 The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13663 The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13674 The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13799 The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping.
6.4
2025-02-19 CVE-2025-1065 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-19 CVE-2024-13443 The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-18 CVE-2024-13743 The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_video shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes.
6.4
2025-02-18 CVE-2025-0622 A flaw was found in command/gpg.
6.4
2025-02-23 CVE-2025-1594 A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1.
6.3
2025-02-23 CVE-2025-1580 A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0.
6.3
2025-02-21 CVE-2025-1544 A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210.
6.3
2025-02-21 CVE-2025-1537 A vulnerability was found in Harpia DiagSystem 12.
6.3
2025-02-18 CVE-2024-13689 The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6.
6.3
2025-02-23 CVE-2025-1597 Mayurik Code Injection vulnerability in Mayurik Best Church Management Software 1.0

A vulnerability was found in SourceCodester Best Church Management Software 1.0.

6.1
2025-02-23 CVE-2025-1592 Mayurik Code Injection vulnerability in Mayurik Best Employee Management System 1.0

A vulnerability was found in SourceCodester Best Employee Management System 1.0.

6.1
2025-02-23 CVE-2025-1591 Razormist Code Injection vulnerability in Razormist Employee Management System 1.0

A vulnerability was found in SourceCodester Employee Management System 1.0.

6.1
2025-02-23 CVE-2025-1589 Janobe Code Injection vulnerability in Janobe E-Learning System 1.0

A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic.

6.1
2025-02-23 CVE-2025-1586 Code Projects Code Injection vulnerability in Code-Projects Blood Bank System 1.0

A vulnerability was found in code-projects Blood Bank System 1.0.

6.1
2025-02-23 CVE-2025-1579 Code Projects Code Injection vulnerability in Code-Projects Blood Bank System 1.0

A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic.

6.1
2025-02-23 CVE-2024-13728 The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping.
6.1
2025-02-22 CVE-2025-0918 Yaycommerce Cross-site Scripting vulnerability in Yaycommerce Yaysmtp

The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping.

6.1
2025-02-22 CVE-2025-0953 Yaycommerce Cross-site Scripting vulnerability in Yaycommerce Yaysmtp 1.0/1.1

The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping.

6.1
2025-02-22 CVE-2024-12467 Grafreak Cross-site Scripting vulnerability in Grafreak Payment BY Redsys

The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters' parameter in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping.

6.1
2025-02-21 CVE-2025-27108 Ryansolid Improper Encoding or Escaping of Output vulnerability in Ryansolid DOM Expressions

dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering.

6.1
2025-02-20 CVE-2024-13888 Amauri Open Redirect vulnerability in Amauri Wpmobile.App

The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56.

6.1
2025-02-19 CVE-2025-20211 A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input.
6.1
2025-02-19 CVE-2025-0916 Yaycommerce Cross-site Scripting vulnerability in Yaycommerce Yaysmtp

The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.2 due to insufficient input sanitization and output escaping.

6.1
2025-02-19 CVE-2024-13363 Raptive Cross-site Scripting vulnerability in Raptive ADS

The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping.

6.1
2025-02-19 CVE-2024-12069 The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.16.
6.1
2025-02-19 CVE-2024-12339 The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping.
6.1
2025-02-19 CVE-2024-13711 BIN CO Cross-site Scripting vulnerability in Bin-Co Pollin

The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient input sanitization and output escaping.

6.1
2025-02-19 CVE-2024-13736 Purechat Cross-site Scripting vulnerability in Purechat Pure Chat

The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWidgetName’ parameter in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping.

6.1
2025-02-19 CVE-2024-13508 The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping.
6.1
2025-02-18 CVE-2025-0521 Wpexperts Cross-site Scripting vulnerability in Wpexperts Post Smtp

The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping.

6.1
2025-02-18 CVE-2025-0817 Ncrafts Cross-site Scripting vulnerability in Ncrafts Formcraft

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping.

6.1
2025-02-18 CVE-2025-0981 Churchcrm Cross-site Scripting vulnerability in Churchcrm

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page.

6.1
2025-02-18 CVE-2024-11376 Clavaque Cross-site Scripting vulnerability in Clavaque S2Member

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114.

6.1
2025-02-18 CVE-2024-13704 Themepoints Cross-site Scripting vulnerability in Themepoints Super Testimonials

The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping.

6.1
2025-02-18 CVE-2025-0864 Pluginus Cross-site Scripting vulnerability in Pluginus Active products Tables for Woocommerce

The Active Products Tables for WooCommerce.

6.1
2025-02-19 CVE-2024-28780 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client  uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
5.9
2025-02-18 CVE-2024-13609 1Clickmigration Unspecified vulnerability in 1Clickmigration 1 Click Migration

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1 via the class-ocm-backup.php.

5.9
2025-02-19 CVE-2025-20153 A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device.
5.8
2025-02-18 CVE-2025-1035 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1.
5.7
2025-02-21 CVE-2025-1470 Eclipse Unspecified vulnerability in Eclipse OMR 0.1

In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory pointers or for memory allocation failures.

5.5
2025-02-17 CVE-2024-13879 The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature.
5.5
2025-02-23 CVE-2025-1577 Code Projects Code Injection vulnerability in Code-Projects Blood Bank System 1.0

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0.

5.4
2025-02-22 CVE-2024-13564 Apollo13 Cross-site Scripting vulnerability in Apollo13 Rife Elementor Extensions & Templates

The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-22 CVE-2024-12038 Themekraft Cross-site Scripting vulnerability in Themekraft Buddyforms

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buddyforms_nav' shortcode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-10222 Benbodhi Cross-site Scripting vulnerability in Benbodhi SVG Support

The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping.

5.4
2025-02-21 CVE-2024-13455 Igumbi Cross-site Scripting vulnerability in Igumbi

The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_calendar' shortcode in all versions up to, and including, 1.40 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2025-1489 Tchgdns Cross-site Scripting vulnerability in Tchgdns Wp-Appbox

The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-12452 Oliverfriedmann Cross-site Scripting vulnerability in Oliverfriedmann Ziggeo

The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-13461 Patternsinthecloud Cross-site Scripting vulnerability in Patternsinthecloud Autoship Cloud

The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-13648 Icopydoc Cross-site Scripting vulnerability in Icopydoc Maps for WP

The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortcode in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2025-1410 Jonathanjernigan Cross-site Scripting vulnerability in Jonathanjernigan PIE Calendar

The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's piecal shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-13379 Covertnine Cross-site Scripting vulnerability in Covertnine C9 Admin Dashboard

The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping.

5.4
2025-02-21 CVE-2024-13388 Tcoderbd Cross-site Scripting vulnerability in Tcoderbd Tcbd Tooltip 1.0

The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-13672 Minicoursegenerator Cross-site Scripting vulnerability in Minicoursegenerator Mini Course Generator

The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2024-13751 Webdevocean Cross-site Scripting vulnerability in Webdevocean 3D Photo Gallery

The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping.

5.4
2025-02-21 CVE-2025-1406 Imamura Cross-site Scripting vulnerability in Imamura Newpost Catch

The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in all versions up to, and including, 1.3.19 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-21 CVE-2025-1407 Amothemo Cross-site Scripting vulnerability in Amothemo AMO Team Showcase

The AMO Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's amoteam_skills shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-20 CVE-2024-49337 IBM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications.

5.4
2025-02-20 CVE-2024-13802 Bandsintown Cross-site Scripting vulnerability in Bandsintown

The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-20 CVE-2024-6432 Vanderwijk Cross-site Scripting vulnerability in Vanderwijk Content Blocks

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping.

5.4
2025-02-20 CVE-2025-1328 Mrlegend1235 Cross-site Scripting vulnerability in Mrlegend1235 Typed JS

The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘typespeed’ parameter in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping.

5.4
2025-02-20 CVE-2025-0897 WOW Company Cross-site Scripting vulnerability in Wow-Company Modal Window

The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 6.1.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-20 CVE-2025-1064 Xootix Cross-site Scripting vulnerability in Xootix Login/Signup Popup

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and including, 2.8.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-20 CVE-2024-13155 Unlimited Elements Cross-site Scripting vulnerability in Unlimited-Elements Unlimited Elements for Elementor

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-20 CVE-2024-13445 Elementor Cross-site Scripting vulnerability in Elementor Website Builder

The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping.

5.4
2025-02-19 CVE-2024-53974 Adobe Cross-site Scripting vulnerability in Adobe Experience Manager

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields.

5.4
2025-02-19 CVE-2024-28776 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting.
5.4
2025-02-19 CVE-2024-13339 Debounce Cross-Site Request Forgery (CSRF) vulnerability in Debounce Email Validator

The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.6.

5.4
2025-02-19 CVE-2024-13679 Getbuybox Cross-site Scripting vulnerability in Getbuybox Buybox Widget

The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' shortcode in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13667 Undsgn Cross-site Scripting vulnerability in Undsgn Uncode

The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping.

5.4
2025-02-18 CVE-2024-13395 Kerryoco Cross-site Scripting vulnerability in Kerryoco Threepress

The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-11895 Vcita Cross-site Scripting vulnerability in Vcita Online Payments - GET Paid With Paypal, Square & Stripe

The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13465 Tusharimran Cross-site Scripting vulnerability in Tusharimran Ablocks

The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" attribute, in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping.

5.4
2025-02-18 CVE-2024-13575 Magazine3 Cross-site Scripting vulnerability in Magazine3 web Stories Enhancer

The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13523 Shenyanzhi Cross-Site Request Forgery (CSRF) vulnerability in Shenyanzhi Memorialday

The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4.

5.4
2025-02-18 CVE-2024-12525 Homeasap Cross-site Scripting vulnerability in Homeasap Easy MLS Listings Import

The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-12813 Pixelgrade Cross-site Scripting vulnerability in Pixelgrade Open Hours

The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'open-hours-current-status' shortcode in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13464 Photonicgnostic Cross-site Scripting vulnerability in Photonicgnostic Library Bookshelves

The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' shortcode in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13501 Formassembly Cross-site Scripting vulnerability in Formassembly Wp-Formassembly

The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13522 Magayo Cross-Site Request Forgery (CSRF) vulnerability in Magayo Lottery Results

The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12.

5.4
2025-02-18 CVE-2024-13565 Shaonback2 Cross-site Scripting vulnerability in Shaonback2 Simple MAP NO API

The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping.

5.4
2025-02-18 CVE-2024-13573 Softdiscover Cross-site Scripting vulnerability in Softdiscover Zigaform

The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13576 Adityapatadia Cross-site Scripting vulnerability in Adityapatadia Gumlet Video

The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13577 Catsone Cross-site Scripting vulnerability in Catsone Cats JOB Listings

The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13578 Infinitescript Cross-site Scripting vulnerability in Infinitescript Wp-Bibtex

The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13579 Platcom Cross-site Scripting vulnerability in Platcom Wp-Asambleas

The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortcode in all versions up to, and including, 2.85.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13581 Supporthost Cross-site Scripting vulnerability in Supporthost Simple Charts

The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13582 Webdevocean Cross-site Scripting vulnerability in Webdevocean Pricing Tables

The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13587 Softdiscover Cross-site Scripting vulnerability in Softdiscover Zigaform

The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_fvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13588 Simplebooklet Cross-site Scripting vulnerability in Simplebooklet

The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simplebooklet' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2025-0805 Mlcalc Cross-site Scripting vulnerability in Mlcalc Mortgage Loan Calculator

The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes.

5.4
2025-02-18 CVE-2024-13741 Metagauss Server-Side Request Forgery (SSRF) vulnerability in Metagauss Profilegrid

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function.

5.4
2025-02-17 CVE-2025-26772 Detheme Cross-site Scripting vulnerability in Detheme Dethemekit for Elementor

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor allows Stored XSS.

5.4
2025-02-23 CVE-2025-1595 A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic.
5.3
2025-02-22 CVE-2025-1361 Ip2Location Improper Authorization vulnerability in Ip2Location Country Blocker

The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function.

5.3
2025-02-22 CVE-2024-13798 Pickplugins Improper Input Validation vulnerability in Pickplugins Comboblocks

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5.

5.3
2025-02-22 CVE-2024-22341 IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management.
5.3
2025-02-21 CVE-2025-1402 Theeventscalendar Missing Authorization vulnerability in Theeventscalendar Event Tickets

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1.

5.3
2025-02-21 CVE-2024-13537 Covertnine Information Exposure Through an Error Message vulnerability in Covertnine C9 Blocks

The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7.

5.3
2025-02-20 CVE-2024-13520 Codemenschen Missing Authorization vulnerability in Codemenschen Gift Vouchers

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6.

5.3
2025-02-20 CVE-2025-1483 Wwexgroup Missing Authorization vulnerability in Wwexgroup LTL Freight Quotes

The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engtz_wd_save_dropship AJAX endpoint in all versions up to, and including, 2.3.12.

5.3
2025-02-19 CVE-2025-27090 Bishopfox Server-Side Request Forgery (SSRF) vulnerability in Bishopfox Sliver

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing.

5.3
2025-02-19 CVE-2025-0968 Wpmet Missing Authorization vulnerability in Wpmet Elementskit Elementor Addons

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function.

5.3
2025-02-19 CVE-2024-13231 Portfoliohub Missing Authorization vulnerability in Portfoliohub

The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_video' function in all versions up to, and including, 1.1.7.

5.3
2025-02-19 CVE-2024-13364 Raptive Missing Authorization vulnerability in Raptive ADS

The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and including, 3.6.3.

5.3
2025-02-19 CVE-2024-13719 Pepro Missing Authorization vulnerability in Pepro Peprodev Ultimate Invoice

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key.

5.3
2025-02-18 CVE-2024-13316 Akashmalik Missing Authorization vulnerability in Akashmalik Scracth & WIN

The Scratch & Win – Giveaways and Contests.

5.3
2025-02-18 CVE-2024-13535 Marcoingraiti Path Traversal vulnerability in Marcoingraiti Actionwear products Sync

The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.0.

5.3
2025-02-18 CVE-2024-13538 Bigbuy Path Traversal vulnerability in Bigbuy Dropshipping Connector for Woocommerce

The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.19.

5.3
2025-02-18 CVE-2024-13540 Byconsole Information Exposure Through an Error Message vulnerability in Byconsole Wooodt Lite

The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1.

5.3
2025-02-17 CVE-2025-1372 A vulnerability was found in GNU elfutils 0.192.
5.3
2025-02-17 CVE-2025-1366 A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical.
5.3
2025-02-17 CVE-2025-1365 A vulnerability, which was classified as critical, was found in GNU elfutils 0.192.
5.3
2025-02-18 CVE-2024-45775 A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list.
5.2
2025-02-21 CVE-2024-13846 Wpindeed SQL Injection vulnerability in Wpindeed Ultimate Learning PRO

The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

4.9
2025-02-19 CVE-2024-13712 BIN CO SQL Injection vulnerability in Bin-Co Pollin

The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

4.9
2025-02-20 CVE-2024-13748 Webcodingplace Cross-site Scripting vulnerability in Webcodingplace Ultimate Classified Listings

The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping.

4.8
2025-02-20 CVE-2024-13849 Dcurasi Cross-site Scripting vulnerability in Dcurasi Cookie Notice BAR

The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping.

4.8
2025-02-19 CVE-2025-1024 Churchcrm Cross-site Scripting vulnerability in Churchcrm

A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page.

4.8
2025-02-18 CVE-2025-1269 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010.
4.8
2025-02-18 CVE-2024-13848 Jakob42 Cross-site Scripting vulnerability in Jakob42 Reaction Buttons

The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping.

4.8
2025-02-17 CVE-2025-26775 Pluginus Cross-site Scripting vulnerability in Pluginus Bear - Woocommerce Bulk Editor and products Manager Professional

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR allows Stored XSS.

4.8
2025-02-22 CVE-2025-1556 A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0.
4.7
2025-02-21 CVE-2025-1548 Iteachyou Code Injection vulnerability in Iteachyou Dreamer CMS 4.1.3

A vulnerability was found in iteachyou Dreamer CMS 4.1.3.

4.6
2025-02-19 CVE-2025-1118 A flaw was found in grub2.
4.4
2025-02-19 CVE-2025-20158 A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device.
4.4
2025-02-18 CVE-2024-45783 A flaw was found in grub2.
4.4
2025-02-23 CVE-2025-1584 A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8.
4.3
2025-02-23 CVE-2025-1575 A vulnerability classified as problematic has been found in Harpia DiagSystem 12.
4.3
2025-02-22 CVE-2025-1557 A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3.
4.3
2025-02-22 CVE-2024-13873 Wpjobportal Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal

The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key.

4.3
2025-02-21 CVE-2025-1543 Iteachyou Path Traversal vulnerability in Iteachyou Dreamer CMS 4.1.3

A vulnerability, which was classified as problematic, has been found in iteachyou Dreamer CMS 4.1.3.

4.3
2025-02-21 CVE-2024-13883 Victorfreitas Cross-Site Request Forgery (CSRF) vulnerability in Victorfreitas Wpupper Share Buttons

The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51.

4.3
2025-02-20 CVE-2024-49344 IBM Session Fixation vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout.

4.3
2025-02-20 CVE-2024-13855 Nilambar Authorization Bypass Through User-Controlled Key vulnerability in Nilambar Prime Addons for Elementor

The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key.

4.3
2025-02-20 CVE-2024-43196 IBM Improper Following of a Certificate's Chain of Trust vulnerability in IBM Openpages With Watson 9.0

IBM OpenPages with Watson 8.3 and 9.0  application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses.

4.3
2025-02-19 CVE-2025-27089 Monospace Incorrect Authorization vulnerability in Monospace Directus

Directus is a real-time API and App dashboard for managing SQL database content.

4.3
2025-02-19 CVE-2024-13336 Exeebit Cross-Site Request Forgery (CSRF) vulnerability in Exeebit Disable Auto Updates

The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.

4.3
2025-02-19 CVE-2024-13405 The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.
4.3
2025-02-19 CVE-2024-13854 Nicheaddons Improper Access Control vulnerability in Nicheaddons Education Addon

The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to missing validation on a user controlled key.

4.3
2025-02-19 CVE-2025-22622 Age Verification for your checkout page.
4.3
2025-02-19 CVE-2025-1447 A vulnerability was found in kasuganosoras Pigeon 1.0.177.
4.3
2025-02-18 CVE-2024-13783 Ncrafts Missing Authorization vulnerability in Ncrafts Formcraft

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11.

4.3
2025-02-18 CVE-2024-13718 Wpdesk Cross-Site Request Forgery (CSRF) vulnerability in Wpdesk Flexible Wishlist for Woocommerce

The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26.

4.3
2025-02-18 CVE-2024-13795 Lightspeedhq Cross-Site Request Forgery (CSRF) vulnerability in Lightspeedhq Ecwid Ecommerce Shopping Cart

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27.

4.3
2025-02-18 CVE-2024-13438 Speedsize Cross-Site Request Forgery (CSRF) vulnerability in Speedsize Image & Video Ai-Optimizer

The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1.

4.3
2025-02-18 CVE-2024-13555 1Clickmigration Cross-Site Request Forgery (CSRF) vulnerability in 1Clickmigration 1 Click Migration

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.

4.3
2025-02-18 CVE-2024-13687 Webdevocean Missing Authorization vulnerability in Webdevocean Team Builder

The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_team_builder_options() function in all versions up to, and including, 1.3.

4.3
2025-02-18 CVE-2025-0796 Kevinbrent Cross-Site Request Forgery (CSRF) vulnerability in Kevinbrent Wprequal

The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.10.

4.3
2025-02-18 CVE-2024-13740 Metagauss Authorization Bypass Through User-Controlled Key vulnerability in Metagauss Profilegrid

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key.

4.3

8 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2025-02-18 CVE-2024-4028 A vulnerability was found in Keycloak.
3.8
2025-02-17 CVE-2025-1392 A vulnerability has been found in D-Link DIR-816 1.01TO and classified as problematic.
3.5
2025-02-22 CVE-2024-45674 IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a local user.
3.3
2025-02-17 CVE-2025-1378 A vulnerability, which was classified as problematic, was found in radare2 5.9.9 33286.
3.3
2025-02-17 CVE-2025-1377 A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192.
3.3
2025-02-17 CVE-2025-1373 A vulnerability was found in FFmpeg up to 7.1.
3.3
2025-02-17 CVE-2025-1376 A vulnerability classified as problematic was found in GNU elfutils 0.192.
2.5
2025-02-23 CVE-2025-1585 A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5.
2.4