Weekly Vulnerabilities Reports > February 17 to 23, 2025
Overview
287 new vulnerabilities reported during this period, including 38 critical vulnerabilities and 61 high severity vulnerabilities. This weekly summary report vulnerabilities in 153 products from 138 vendors including Wegia, Eniture, IBM, Churchcrm, and Tenda. Vulnerabilities are notably categorized as "Cross-site Scripting", "SQL Injection", "Cross-Site Request Forgery (CSRF)", "Code Injection", and "Missing Authorization".
- 267 reported vulnerabilities are remotely exploitables.
- 161 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
- 139 reported vulnerabilities are exploitable by an anonymous user.
- Wegia has the most reported vulnerabilities, with 13 reported vulnerabilities.
- Wegia has the most reported critical vulnerabilities, with 10 reported vulnerabilities.
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
VULNERABILITIES
EXPLOITABLE
EXPLOITABLE
AVAILABLE
ANONYMOUSLY
WEB APPLICATION
Vulnerability Details
The following table list reported vulnerabilities for the period covered by this report:
38 Critical Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-02-23 | CVE-2025-1596 | Mayurik | Injection vulnerability in Mayurik Best Church Management Software 1.0 A vulnerability was found in SourceCodester Best Church Management Software 1.0 and classified as critical. | 9.8 |
2025-02-23 | CVE-2025-1593 | Mayurik | Unrestricted Upload of File with Dangerous Type vulnerability in Mayurik Best Employee Management System 1.0 A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. | 9.8 |
2025-02-23 | CVE-2025-1582 | Phpgurukul | Injection vulnerability in PHPgurukul Online Nurse Hiring System 1.0 A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. | 9.8 |
2025-02-23 | CVE-2025-1583 | Phpgurukul | Injection vulnerability in PHPgurukul Online Nurse Hiring System 1.0 A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. | 9.8 |
2025-02-23 | CVE-2025-1581 | Phpgurukul | Injection vulnerability in PHPgurukul Online Nurse Hiring System 1.0 A vulnerability was found in PHPGurukul Online Nurse Hiring System 1.0. | 9.8 |
2025-02-23 | CVE-2025-1576 | Fabianros | Injection vulnerability in Fabianros Real Estate Property Management System 1.0 A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. | 9.8 |
2025-02-22 | CVE-2025-1509 | Wpguru | Code Injection vulnerability in Wpguru Show ME the Cookies 1.0 The The Show Me The Cookies plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0. | 9.8 |
2025-02-22 | CVE-2025-1510 | Keesiemeijer | Code Injection vulnerability in Keesiemeijer Custom Post Type Date Archives The The Custom Post Type Date Archives plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.7.1. | 9.8 |
2025-02-21 | CVE-2025-1539 | Dlink | Out-of-bounds Write vulnerability in Dlink Dap-1320 Firmware 1.0 A vulnerability, which was classified as critical, has been found in D-Link DAP-1320 1.00. | 9.8 |
2025-02-20 | CVE-2025-25663 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 A vulnerability was found in Tenda AC8V4 V16.03.34.06. | 9.8 |
2025-02-20 | CVE-2025-25664 | Tenda | Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function. | 9.8 |
2025-02-20 | CVE-2025-25667 | Tenda | Classic Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info. | 9.8 |
2025-02-20 | CVE-2025-25668 | Tenda | Classic Buffer Overflow vulnerability in Tenda AC8 Firmware 16.03.34.06 Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function. | 9.8 |
2025-02-20 | CVE-2025-25674 | Tenda | Classic Buffer Overflow vulnerability in Tenda Ac10 Firmware 15.03.06.23 Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid. | 9.8 |
2025-02-20 | CVE-2025-25675 | Tenda | Command Injection vulnerability in Tenda Ac10 Firmware 15.03.06.23 Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. | 9.8 |
2025-02-20 | CVE-2025-27096 | Wegia | SQL Injection vulnerability in Wegia 3.2.13 WeGIA is a Web Manager for Institutions with a focus on Portuguese language. | 9.8 |
2025-02-20 | CVE-2024-13789 | Matiskiba | Deserialization of Untrusted Data vulnerability in Matiskiba Ravpage The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted input from the 'paramsv2' parameter. | 9.8 |
2025-02-20 | CVE-2024-13792 | EX Themes | Code Injection vulnerability in Ex-Themes Woocommerce Food The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. | 9.8 |
2025-02-19 | CVE-2025-21355 | Microsoft | Missing Authentication for Critical Function vulnerability in Microsoft Bing Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network | 9.8 |
2025-02-19 | CVE-2025-24989 | Microsoft | Unspecified vulnerability in Microsoft Power Pages An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. This vulnerability has already been mitigated in the service and all affected customers have been notified. | 9.8 |
2025-02-18 | CVE-2025-26606 | Wegia | Improper Access Control vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26607 | Wegia | Improper Access Control vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26608 | Wegia | Improper Access Control vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26609 | Wegia | Improper Access Control vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26610 | Wegia | SQL Injection vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26611 | Wegia | Improper Access Control vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26612 | Wegia | SQL Injection vulnerability in Wegia WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26613 | Wegia | Improper Access Control vulnerability in Wegia 3.2.13 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2025-26617 | Wegia | Improper Access Control vulnerability in Wegia 3.2.13 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 9.8 |
2025-02-18 | CVE-2024-13797 | Presslayouts | Code Injection vulnerability in Presslayouts Pressmart The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. | 9.8 |
2025-02-18 | CVE-2025-1023 | Churchcrm | SQL Injection vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. | 9.8 |
2025-02-18 | CVE-2024-12860 | Carspot Project | Unspecified vulnerability in Carspot Project Carspot The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. | 9.8 |
2025-02-18 | CVE-2024-13556 | Wecantrack | Deserialization of Untrusted Data vulnerability in Wecantrack Affiliate Links The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export. | 9.8 |
2025-02-18 | CVE-2024-13725 | Keap | Path Traversal vulnerability in Keap Official OPT in Forms The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. | 9.8 |
2025-02-17 | CVE-2025-1379 | Code Projects | SQL Injection vulnerability in Code-Projects Real Estate Property Management System 1.0 A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. | 9.8 |
2025-02-17 | CVE-2025-1380 | Codezips | SQL Injection vulnerability in Codezips GYM Management System 1.0 A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. | 9.8 |
2025-02-17 | CVE-2025-1387 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user. | 9.8 | |
2025-02-23 | CVE-2025-1588 | Phpgurukul | Path Traversal: '../filedir' vulnerability in PHPgurukul Online Nurse Hiring System 1.0 A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. | 9.1 |
61 High Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-02-21 | CVE-2025-1538 | Dlink | Out-of-bounds Write vulnerability in Dlink Dap-1320 Firmware 1.0 A vulnerability classified as critical was found in D-Link DAP-1320 1.00. | 8.8 |
2025-02-21 | CVE-2024-13353 | Cyberchimps | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Cyberchimps Responsive Addons for Elementor The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via several widgets. | 8.8 |
2025-02-20 | CVE-2024-49779 | IBM | Cross-Site Request Forgery (CSRF) vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation and management of authentication cookies. | 8.8 |
2025-02-20 | CVE-2024-13753 | Webcodingplace | Cross-Site Request Forgery (CSRF) vulnerability in Webcodingplace Ultimate Classified Listings The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. | 8.8 |
2025-02-19 | CVE-2024-28777 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. | 8.8 | |
2025-02-19 | CVE-2024-52902 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application contains hard coded database passwords in source code which could be used for unauthorized access to the system. | 8.8 | |
2025-02-19 | CVE-2025-1132 | Churchcrm | SQL Injection vulnerability in Churchcrm A time-based blind SQL Injection vulnerability exists in the ChurchCRM 5.13.0 and prior EditEventAttendees.php within the EN_tyid parameter. | 8.8 |
2025-02-19 | CVE-2025-1441 | Royal Elementor Addons | Cross-Site Request Forgery (CSRF) vulnerability in Royal-Elementor-Addons Royal Elementor Addons The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1007. | 8.8 |
2025-02-18 | CVE-2025-26614 | Wegia | SQL Injection vulnerability in Wegia 3.2.13 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 8.8 |
2025-02-18 | CVE-2024-13636 | Unitedthemes | Deserialization of Untrusted Data vulnerability in Unitedthemes Brooklyn 4.9.7.6 The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.9.2 via deserialization of untrusted input in the ot_decode function. | 8.8 |
2025-02-18 | CVE-2024-13369 | Goodlayers | SQL Injection vulnerability in Goodlayers Tour Master The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the ‘review_id’ parameter in all versions up to, and including, 5.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 8.8 |
2025-02-18 | CVE-2024-13315 | Shopwarden | Cross-Site Request Forgery (CSRF) vulnerability in Shopwarden The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. | 8.8 |
2025-02-18 | CVE-2024-13677 | Istmoplugins | Missing Authorization vulnerability in Istmoplugins GET Bookings WP The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.27. | 8.8 |
2025-02-18 | CVE-2024-13852 | Backie | Cross-Site Request Forgery (CSRF) vulnerability in Backie Option Editor The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. | 8.8 |
2025-02-17 | CVE-2025-1389 | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | 8.8 | |
2025-02-17 | CVE-2025-1388 | Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells | 8.8 | |
2025-02-20 | CVE-2024-49782 | IBM | Improper Validation of Certificate with Host Mismatch vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 could allow a remote attacker to spoof mail server identity when using SSL/TLS security. | 8.2 |
2025-02-19 | CVE-2023-47160 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. | 8.2 | |
2025-02-18 | CVE-2024-13684 | Smartzminds | Cross-Site Request Forgery (CSRF) vulnerability in Smartzminds Reset The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. | 8.1 |
2025-02-19 | CVE-2024-45084 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated attacker to conduct formula injection. | 8.0 | |
2025-02-21 | CVE-2025-1471 | Eclipse | Unspecified vulnerability in Eclipse OMR In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. | 7.8 |
2025-02-23 | CVE-2025-1578 | Phpgurukul | Injection vulnerability in PHPgurukul Online Shopping Portal 2.1 A vulnerability, which was classified as critical, was found in PHPGurukul Online Shopping Portal 2.1. | 7.5 |
2025-02-22 | CVE-2024-13474 | The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 | |
2025-02-21 | CVE-2024-11260 | Pixelite | SQL Injection vulnerability in Pixelite Events Manager The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-21 | CVE-2024-13818 | Genetechsolutions | Information Exposure Through Log Files vulnerability in Genetechsolutions PIE Register The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.3.9 through publicly exposed log files. | 7.5 |
2025-02-20 | CVE-2025-27097 | THE Guild | Resource Exhaustion vulnerability in The-Guild Graphql Mesh GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. | 7.5 |
2025-02-20 | CVE-2025-27098 | THE Guild | Path Traversal vulnerability in The-Guild Graphql Mesh CLI and Graphql Mesh Http GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. | 7.5 |
2025-02-20 | CVE-2025-27091 | Cisco | Heap-based Buffer Overflow vulnerability in Cisco Openh264 OpenH264 is a free license codec library which supports H.264 encoding and decoding. | 7.5 |
2025-02-20 | CVE-2024-13476 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_dropship' AJAX endpoint in all versions up to, and including, 2.3.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2025-27092 | CMU | Path Traversal vulnerability in CMU Ghosts GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. | 7.5 |
2025-02-19 | CVE-2024-13478 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13479 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.2.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13481 | The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 | |
2025-02-19 | CVE-2024-13483 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 2.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13485 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13491 | Eniture | SQL Injection vulnerability in Eniture Small Package Quotes The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13533 | Eniture | SQL Injection vulnerability in Eniture Small Package Quotes The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13534 | Eniture | SQL Injection vulnerability in Eniture Small Package Quotes The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 5.2.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13489 | Eniture | SQL Injection vulnerability in Eniture LTL Freight Quotes The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 4.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 7.5 |
2025-02-19 | CVE-2024-13468 | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. | 7.5 | |
2025-02-19 | CVE-2024-13592 | The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the 'team-builder-vc' shortcode. | 7.5 | |
2025-02-18 | CVE-2025-27113 | Xmlsoft | Unspecified vulnerability in Xmlsoft Libxml2 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a NULL pointer dereference in xmlPatMatch in pattern.c. | 7.5 |
2025-02-18 | CVE-2025-26615 | Wegia | Improper Access Control vulnerability in Wegia 3.2.13 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 7.5 |
2025-02-18 | CVE-2025-26616 | Wegia | Improper Access Control vulnerability in Wegia 3.2.13 WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. | 7.5 |
2025-02-18 | CVE-2024-13681 | Undsgn | Unspecified vulnerability in Undsgn Uncode The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and including, 2.9.1.6. | 7.5 |
2025-02-18 | CVE-2024-13622 | Imaginate Solutions | Unspecified vulnerability in Imaginate-Solutions File Uploads Addon for Woocommerce The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the 'uploads' directory. | 7.5 |
2025-02-17 | CVE-2025-1374 | Fabianros | SQL Injection vulnerability in Fabianros Real Estate Property Management System 1.0 A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. | 7.5 |
2025-02-21 | CVE-2025-1536 | A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. | 7.3 | |
2025-02-21 | CVE-2025-1535 | A vulnerability was found in Baiyi Cloud Asset Management System 8.142.100.161. | 7.3 | |
2025-02-19 | CVE-2025-1464 | A vulnerability, which was classified as critical, has been found in Baiyi Cloud Asset Management System up to 20250204. | 7.3 | |
2025-02-19 | CVE-2025-1448 | A vulnerability was found in Synway SMG Gateway Management Software up to 20250204. | 7.3 | |
2025-02-23 | CVE-2025-1590 | Janobe | Unrestricted Upload of File with Dangerous Type vulnerability in Janobe E-Learning System 1.0 A vulnerability was found in SourceCodester E-Learning System 1.0. | 7.2 |
2025-02-22 | CVE-2025-0957 | The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. | 7.2 | |
2025-02-22 | CVE-2024-13899 | Misterpah | Deserialization of Untrusted Data vulnerability in Misterpah Mambo Joomla Importer 1.0 The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. | 7.2 |
2025-02-21 | CVE-2024-13900 | Satollo | Code Injection vulnerability in Satollo Head, Footer, and Post Injections The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. | 7.2 |
2025-02-19 | CVE-2025-1133 | Churchcrm | SQL Injection vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based blind SQL Injection vulnerability in the EditEventAttendees functionality. | 7.2 |
2025-02-19 | CVE-2025-1134 | Churchcrm | SQL Injection vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. | 7.2 |
2025-02-19 | CVE-2025-1135 | Churchcrm | SQL Injection vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0. | 7.2 |
2025-02-19 | CVE-2024-11582 | The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ip parameter in all versions up to, and including, 10.43 due to insufficient input sanitization and output escaping. | 7.2 | |
2025-02-17 | CVE-2025-0924 | The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. | 7.2 | |
2025-02-20 | CVE-2024-49781 | IBM | XXE vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. | 7.1 |
180 Medium Vulnerabilities
DATE | CVE | VENDOR | VULNERABILITY | CVSS |
---|---|---|---|---|
2025-02-18 | CVE-2025-26465 | Openbsd Debian Redhat Netapp | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. | 6.8 |
2025-02-19 | CVE-2024-45777 | A flaw was found in grub2. | 6.7 | |
2025-02-18 | CVE-2024-45776 | When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. | 6.7 | |
2025-02-19 | CVE-2025-1465 | Lmxcms | Code Injection vulnerability in Lmxcms 1.41 A vulnerability, which was classified as problematic, was found in lmxcms 1.41. | 6.6 |
2025-02-21 | CVE-2024-13713 | Wpexperts | SQL Injection vulnerability in Wpexperts Givewp Square The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versions up to, and including, 1.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-21 | CVE-2024-12276 | Ultimatemember | SQL Injection vulnerability in Ultimatemember Ultimate Member The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to second-order SQL Injection via filenames in all versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-21 | CVE-2024-13235 | Pinpoint | SQL Injection vulnerability in Pinpoint Booking System The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'language' parameter in all versions up to, and including, 2.9.9.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-20 | CVE-2025-0866 | Legoeso | SQL Injection vulnerability in Legoeso PDF Manager The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-20 | CVE-2024-49355 | IBM | Improper Output Neutralization for Logs vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 may write improperly neutralized data to server log files when the tracing is enabled per the System Tracing feature. | 6.5 |
2025-02-20 | CVE-2024-49780 | IBM | Unspecified vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to traverse directories on the system. | 6.5 |
2025-02-19 | CVE-2024-45081 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modify restricted content due to incorrect authorization checks. | 6.5 | |
2025-02-19 | CVE-2024-13676 | The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 | |
2025-02-19 | CVE-2025-0865 | DE Baat | Cross-Site Request Forgery (CSRF) vulnerability in De-Baat WP Media Category Management The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. | 6.5 |
2025-02-18 | CVE-2024-13691 | Undsgn | Unspecified vulnerability in Undsgn Uncode The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. | 6.5 |
2025-02-18 | CVE-2024-13595 | Modalsurvey | SQL Injection vulnerability in Modalsurvey Simple Signup Form The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 6.5 |
2025-02-20 | CVE-2025-1043 | The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode. | 6.4 | |
2025-02-19 | CVE-2025-0677 | A flaw was found in grub2. | 6.4 | |
2025-02-19 | CVE-2024-11335 | The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-11753 | The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-11778 | The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-12522 | The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13390 | The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13462 | The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13589 | The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13591 | The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13657 | The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, 20200131 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13660 | The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, 2.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13663 | The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13674 | The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13799 | The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. | 6.4 | |
2025-02-19 | CVE-2025-1065 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Import Data From File feature in all versions up to, and including, 3.11.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-19 | CVE-2024-13443 | The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shortcode in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-18 | CVE-2024-13743 | The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_video shortcode in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 6.4 | |
2025-02-18 | CVE-2025-0622 | A flaw was found in command/gpg. | 6.4 | |
2025-02-23 | CVE-2025-1594 | A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. | 6.3 | |
2025-02-23 | CVE-2025-1580 | A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. | 6.3 | |
2025-02-21 | CVE-2025-1544 | A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210. | 6.3 | |
2025-02-21 | CVE-2025-1537 | A vulnerability was found in Harpia DiagSystem 12. | 6.3 | |
2025-02-18 | CVE-2024-13689 | The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.9.1.6. | 6.3 | |
2025-02-23 | CVE-2025-1597 | Mayurik | Code Injection vulnerability in Mayurik Best Church Management Software 1.0 A vulnerability was found in SourceCodester Best Church Management Software 1.0. | 6.1 |
2025-02-23 | CVE-2025-1592 | Mayurik | Code Injection vulnerability in Mayurik Best Employee Management System 1.0 A vulnerability was found in SourceCodester Best Employee Management System 1.0. | 6.1 |
2025-02-23 | CVE-2025-1591 | Razormist | Code Injection vulnerability in Razormist Employee Management System 1.0 A vulnerability was found in SourceCodester Employee Management System 1.0. | 6.1 |
2025-02-23 | CVE-2025-1589 | Janobe | Code Injection vulnerability in Janobe E-Learning System 1.0 A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. | 6.1 |
2025-02-23 | CVE-2025-1586 | Code Projects | Code Injection vulnerability in Code-Projects Blood Bank System 1.0 A vulnerability was found in code-projects Blood Bank System 1.0. | 6.1 |
2025-02-23 | CVE-2025-1579 | Code Projects | Code Injection vulnerability in Code-Projects Blood Bank System 1.0 A vulnerability was found in code-projects Blood Bank System 1.0 and classified as problematic. | 6.1 |
2025-02-23 | CVE-2024-13728 | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. | 6.1 | |
2025-02-22 | CVE-2025-0918 | Yaycommerce | Cross-site Scripting vulnerability in Yaycommerce Yaysmtp The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-22 | CVE-2025-0953 | Yaycommerce | Cross-site Scripting vulnerability in Yaycommerce Yaysmtp 1.0/1.1 The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-22 | CVE-2024-12467 | Grafreak | Cross-site Scripting vulnerability in Grafreak Payment BY Redsys The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters' parameter in all versions up to, and including, 1.0.12 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-21 | CVE-2025-27108 | Ryansolid | Improper Encoding or Escaping of Output vulnerability in Ryansolid DOM Expressions dom-expressions is a Fine-Grained Runtime for Performant DOM Rendering. | 6.1 |
2025-02-20 | CVE-2024-13888 | Amauri | Open Redirect vulnerability in Amauri Wpmobile.App The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. | 6.1 |
2025-02-19 | CVE-2025-20211 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. | 6.1 | |
2025-02-19 | CVE-2025-0916 | Yaycommerce | Cross-site Scripting vulnerability in Yaycommerce Yaysmtp The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.2 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-19 | CVE-2024-13363 | Raptive | Cross-site Scripting vulnerability in Raptive ADS The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-19 | CVE-2024-12069 | The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.16. | 6.1 | |
2025-02-19 | CVE-2024-12339 | The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. | 6.1 | |
2025-02-19 | CVE-2024-13711 | BIN CO | Cross-site Scripting vulnerability in Bin-Co Pollin The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-19 | CVE-2024-13736 | Purechat | Cross-site Scripting vulnerability in Purechat Pure Chat The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWidgetName’ parameter in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-19 | CVE-2024-13508 | The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping. | 6.1 | |
2025-02-18 | CVE-2025-0521 | Wpexperts | Cross-site Scripting vulnerability in Wpexperts Post Smtp The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-18 | CVE-2025-0817 | Ncrafts | Cross-site Scripting vulnerability in Ncrafts Formcraft The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.9.11 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-18 | CVE-2025-0981 | Churchcrm | Cross-site Scripting vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. | 6.1 |
2025-02-18 | CVE-2024-11376 | Clavaque | Cross-site Scripting vulnerability in Clavaque S2Member The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. | 6.1 |
2025-02-18 | CVE-2024-13704 | Themepoints | Cross-site Scripting vulnerability in Themepoints Super Testimonials The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. | 6.1 |
2025-02-18 | CVE-2025-0864 | Pluginus | Cross-site Scripting vulnerability in Pluginus Active products Tables for Woocommerce The Active Products Tables for WooCommerce. | 6.1 |
2025-02-19 | CVE-2024-28780 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 5.9 | |
2025-02-18 | CVE-2024-13609 | 1Clickmigration | Unspecified vulnerability in 1Clickmigration 1 Click Migration The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1 via the class-ocm-backup.php. | 5.9 |
2025-02-19 | CVE-2025-20153 | A vulnerability in the email filtering mechanism of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to bypass the configured rules and allow emails that should have been denied to flow through an affected device. | 5.8 | |
2025-02-18 | CVE-2025-1035 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog Server allows Manipulating Web Input to File System Calls.This issue affects KLog Server: before 3.1.1. | 5.7 | |
2025-02-21 | CVE-2025-1470 | Eclipse | Unspecified vulnerability in Eclipse OMR 0.1 In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory pointers or for memory allocation failures. | 5.5 |
2025-02-17 | CVE-2024-13879 | The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2 due to insufficient validation on the webhook feature. | 5.5 | |
2025-02-23 | CVE-2025-1577 | Code Projects | Code Injection vulnerability in Code-Projects Blood Bank System 1.0 A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. | 5.4 |
2025-02-22 | CVE-2024-13564 | Apollo13 | Cross-site Scripting vulnerability in Apollo13 Rife Elementor Extensions & Templates The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Writing Effect Headline shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-22 | CVE-2024-12038 | Themekraft | Cross-site Scripting vulnerability in Themekraft Buddyforms The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buddyforms_nav' shortcode in all versions up to, and including, 2.8.15 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-10222 | Benbodhi | Cross-site Scripting vulnerability in Benbodhi SVG Support The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.5.10 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-21 | CVE-2024-13455 | Igumbi | Cross-site Scripting vulnerability in Igumbi The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_calendar' shortcode in all versions up to, and including, 1.40 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2025-1489 | Tchgdns | Cross-site Scripting vulnerability in Tchgdns Wp-Appbox The WP-Appbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's appbox shortcode in all versions up to, and including, 4.5.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-12452 | Oliverfriedmann | Cross-site Scripting vulnerability in Oliverfriedmann Ziggeo The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-13461 | Patternsinthecloud | Cross-site Scripting vulnerability in Patternsinthecloud Autoship Cloud The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-13648 | Icopydoc | Cross-site Scripting vulnerability in Icopydoc Maps for WP The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortcode in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2025-1410 | Jonathanjernigan | Cross-site Scripting vulnerability in Jonathanjernigan PIE Calendar The Events Calendar Made Simple – Pie Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's piecal shortcode in all versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-13379 | Covertnine | Cross-site Scripting vulnerability in Covertnine C9 Admin Dashboard The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-21 | CVE-2024-13388 | Tcoderbd | Cross-site Scripting vulnerability in Tcoderbd Tcbd Tooltip 1.0 The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-13672 | Minicoursegenerator | Cross-site Scripting vulnerability in Minicoursegenerator Mini Course Generator The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mcg' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2024-13751 | Webdevocean | Cross-site Scripting vulnerability in Webdevocean 3D Photo Gallery The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-21 | CVE-2025-1406 | Imamura | Cross-site Scripting vulnerability in Imamura Newpost Catch The Newpost Catch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's npc shortcode in all versions up to, and including, 1.3.19 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-21 | CVE-2025-1407 | Amothemo | Cross-site Scripting vulnerability in Amothemo AMO Team Showcase The AMO Team Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's amoteam_skills shortcode in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-20 | CVE-2024-49337 | IBM | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications. | 5.4 |
2025-02-20 | CVE-2024-13802 | Bandsintown | Cross-site Scripting vulnerability in Bandsintown The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-20 | CVE-2024-6432 | Vanderwijk | Cross-site Scripting vulnerability in Vanderwijk Content Blocks The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter within the plugin's shortcode Content Block in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-20 | CVE-2025-1328 | Mrlegend1235 | Cross-site Scripting vulnerability in Mrlegend1235 Typed JS The Typed JS: A typewriter style animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘typespeed’ parameter in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-20 | CVE-2025-0897 | WOW Company | Cross-site Scripting vulnerability in Wow-Company Modal Window The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 6.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-20 | CVE-2025-1064 | Xootix | Cross-site Scripting vulnerability in Xootix Login/Signup Popup The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and including, 2.8.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-20 | CVE-2024-13155 | Unlimited Elements | Cross-site Scripting vulnerability in Unlimited-Elements Unlimited Elements for Elementor The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Transparent Split Hero widget in all versions up to, and including, 1.5.140 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-20 | CVE-2024-13445 | Elementor | Cross-site Scripting vulnerability in Elementor Website Builder The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the border, margin and gap parameters in all versions up to, and including, 3.27.4 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-19 | CVE-2024-53974 | Adobe | Cross-site Scripting vulnerability in Adobe Experience Manager Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. | 5.4 |
2025-02-19 | CVE-2024-28776 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. | 5.4 | |
2025-02-19 | CVE-2024-13339 | Debounce | Cross-Site Request Forgery (CSRF) vulnerability in Debounce Email Validator The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.6. | 5.4 |
2025-02-19 | CVE-2024-13679 | Getbuybox | Cross-site Scripting vulnerability in Getbuybox Buybox Widget The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' shortcode in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13667 | Undsgn | Cross-site Scripting vulnerability in Undsgn Uncode The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-18 | CVE-2024-13395 | Kerryoco | Cross-site Scripting vulnerability in Kerryoco Threepress The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-11895 | Vcita | Cross-site Scripting vulnerability in Vcita Online Payments - GET Paid With Paypal, Square & Stripe The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13465 | Tusharimran | Cross-site Scripting vulnerability in Tusharimran Ablocks The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Table Of Content" Block, specifically in the "markerView" attribute, in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-18 | CVE-2024-13575 | Magazine3 | Cross-site Scripting vulnerability in Magazine3 web Stories Enhancer The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'web_stories_enhancer' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13523 | Shenyanzhi | Cross-Site Request Forgery (CSRF) vulnerability in Shenyanzhi Memorialday The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. | 5.4 |
2025-02-18 | CVE-2024-12525 | Homeasap | Cross-site Scripting vulnerability in Homeasap Easy MLS Listings Import The Easy MLS Listings Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-featured-listings' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-12813 | Pixelgrade | Cross-site Scripting vulnerability in Pixelgrade Open Hours The Open Hours – Easy Opening Hours plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'open-hours-current-status' shortcode in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13464 | Photonicgnostic | Cross-site Scripting vulnerability in Photonicgnostic Library Bookshelves The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' shortcode in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13501 | Formassembly | Cross-site Scripting vulnerability in Formassembly Wp-Formassembly The WP-FormAssembly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'formassembly' shortcode in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13522 | Magayo | Cross-Site Request Forgery (CSRF) vulnerability in Magayo Lottery Results The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. | 5.4 |
2025-02-18 | CVE-2024-13565 | Shaonback2 | Cross-site Scripting vulnerability in Shaonback2 Simple MAP NO API The Simple Map No Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. | 5.4 |
2025-02-18 | CVE-2024-13573 | Softdiscover | Cross-site Scripting vulnerability in Softdiscover Zigaform The Zigaform – Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_rfvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13576 | Adityapatadia | Cross-site Scripting vulnerability in Adityapatadia Gumlet Video The Gumlet Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gumlet' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13577 | Catsone | Cross-site Scripting vulnerability in Catsone Cats JOB Listings The CATS Job Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catsone' shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13578 | Infinitescript | Cross-site Scripting vulnerability in Infinitescript Wp-Bibtex The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13579 | Platcom | Cross-site Scripting vulnerability in Platcom Wp-Asambleas The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortcode in all versions up to, and including, 2.85.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13581 | Supporthost | Cross-site Scripting vulnerability in Supporthost Simple Charts The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13582 | Webdevocean | Cross-site Scripting vulnerability in Webdevocean Pricing Tables The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wdo_simple_pricing_table_free' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13587 | Softdiscover | Cross-site Scripting vulnerability in Softdiscover Zigaform The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_fvar' shortcode in all versions up to, and including, 7.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13588 | Simplebooklet | Cross-site Scripting vulnerability in Simplebooklet The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simplebooklet' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2025-0805 | Mlcalc | Cross-site Scripting vulnerability in Mlcalc Mortgage Loan Calculator The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. | 5.4 |
2025-02-18 | CVE-2024-13741 | Metagauss | Server-Side Request Forgery (SSRF) vulnerability in Metagauss Profilegrid The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. | 5.4 |
2025-02-17 | CVE-2025-26772 | Detheme | Cross-site Scripting vulnerability in Detheme Dethemekit for Elementor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Detheme DethemeKit For Elementor allows Stored XSS. | 5.4 |
2025-02-23 | CVE-2025-1595 | A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified as problematic. | 5.3 | |
2025-02-22 | CVE-2025-1361 | Ip2Location | Improper Authorization vulnerability in Ip2Location Country Blocker The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. | 5.3 |
2025-02-22 | CVE-2024-13798 | Pickplugins | Improper Input Validation vulnerability in Pickplugins Comboblocks The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in all versions up to, and including, 2.3.5. | 5.3 |
2025-02-22 | CVE-2024-22341 | IBM Watson Query on Cloud Pak for Data 4.0.0 through 4.0.9, 4.5.0 through 4.5.3, 4.6.0 through 4.6.6, 4.7.0 through 4.7.4, and 4.8.0 through 4.8.7 could allow unauthorized data access from a remote data source object due to improper privilege management. | 5.3 | |
2025-02-21 | CVE-2025-1402 | Theeventscalendar | Missing Authorization vulnerability in Theeventscalendar Event Tickets The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. | 5.3 |
2025-02-21 | CVE-2024-13537 | Covertnine | Information Exposure Through an Error Message vulnerability in Covertnine C9 Blocks The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. | 5.3 |
2025-02-20 | CVE-2024-13520 | Codemenschen | Missing Authorization vulnerability in Codemenschen Gift Vouchers The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the 'update_voucher_price', 'update_voucher_date', 'update_voucher_note' functions in all versions up to, and including, 4.4.6. | 5.3 |
2025-02-20 | CVE-2025-1483 | Wwexgroup | Missing Authorization vulnerability in Wwexgroup LTL Freight Quotes The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the engtz_wd_save_dropship AJAX endpoint in all versions up to, and including, 2.3.12. | 5.3 |
2025-02-19 | CVE-2025-27090 | Bishopfox | Server-Side Request Forgery (SSRF) vulnerability in Bishopfox Sliver Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. | 5.3 |
2025-02-19 | CVE-2025-0968 | Wpmet | Missing Authorization vulnerability in Wpmet Elementskit Elementor Addons The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. | 5.3 |
2025-02-19 | CVE-2024-13231 | Portfoliohub | Missing Authorization vulnerability in Portfoliohub The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_video' function in all versions up to, and including, 1.1.7. | 5.3 |
2025-02-19 | CVE-2024-13364 | Raptive | Missing Authorization vulnerability in Raptive ADS The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_ads_files_reset() and cls_file_reset() functions in all versions up to, and including, 3.6.3. | 5.3 |
2025-02-19 | CVE-2024-13719 | Pepro | Missing Authorization vulnerability in Pepro Peprodev Ultimate Invoice The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. | 5.3 |
2025-02-18 | CVE-2024-13316 | Akashmalik | Missing Authorization vulnerability in Akashmalik Scracth & WIN The Scratch & Win – Giveaways and Contests. | 5.3 |
2025-02-18 | CVE-2024-13535 | Marcoingraiti | Path Traversal vulnerability in Marcoingraiti Actionwear products Sync The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.3.0. | 5.3 |
2025-02-18 | CVE-2024-13538 | Bigbuy | Path Traversal vulnerability in Bigbuy Dropshipping Connector for Woocommerce The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.19. | 5.3 |
2025-02-18 | CVE-2024-13540 | Byconsole | Information Exposure Through an Error Message vulnerability in Byconsole Wooodt Lite The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. | 5.3 |
2025-02-17 | CVE-2025-1372 | A vulnerability was found in GNU elfutils 0.192. | 5.3 | |
2025-02-17 | CVE-2025-1366 | A vulnerability was found in MicroWord eScan Antivirus 7.0.32 on Linux and classified as critical. | 5.3 | |
2025-02-17 | CVE-2025-1365 | A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. | 5.3 | |
2025-02-18 | CVE-2024-45775 | A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. | 5.2 | |
2025-02-21 | CVE-2024-13846 | Wpindeed | SQL Injection vulnerability in Wpindeed Ultimate Learning PRO The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 |
2025-02-19 | CVE-2024-13712 | BIN CO | SQL Injection vulnerability in Bin-Co Pollin The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and including, 1.01.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. | 4.9 |
2025-02-20 | CVE-2024-13748 | Webcodingplace | Cross-site Scripting vulnerability in Webcodingplace Ultimate Classified Listings The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. | 4.8 |
2025-02-20 | CVE-2024-13849 | Dcurasi | Cross-site Scripting vulnerability in Dcurasi Cookie Notice BAR The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. | 4.8 |
2025-02-19 | CVE-2025-1024 | Churchcrm | Cross-site Scripting vulnerability in Churchcrm A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. | 4.8 |
2025-02-18 | CVE-2025-1269 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing.This issue affects Liman MYS: before 2.1.1 - 1010. | 4.8 | |
2025-02-18 | CVE-2024-13848 | Jakob42 | Cross-site Scripting vulnerability in Jakob42 Reaction Buttons The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. | 4.8 |
2025-02-17 | CVE-2025-26775 | Pluginus | Cross-site Scripting vulnerability in Pluginus Bear - Woocommerce Bulk Editor and products Manager Professional Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR allows Stored XSS. | 4.8 |
2025-02-22 | CVE-2025-1556 | A vulnerability, which was classified as problematic, has been found in westboy CicadasCMS 1.0. | 4.7 | |
2025-02-21 | CVE-2025-1548 | Iteachyou | Code Injection vulnerability in Iteachyou Dreamer CMS 4.1.3 A vulnerability was found in iteachyou Dreamer CMS 4.1.3. | 4.6 |
2025-02-19 | CVE-2025-1118 | A flaw was found in grub2. | 4.4 | |
2025-02-19 | CVE-2025-20158 | A vulnerability in the debug shell of Cisco Video Phone 8875 and Cisco Desk Phone 9800 Series could allow an authenticated, local attacker to access sensitive information on an affected device. | 4.4 | |
2025-02-18 | CVE-2024-45783 | A flaw was found in grub2. | 4.4 | |
2025-02-23 | CVE-2025-1584 | A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. | 4.3 | |
2025-02-23 | CVE-2025-1575 | A vulnerability classified as problematic has been found in Harpia DiagSystem 12. | 4.3 | |
2025-02-22 | CVE-2025-1557 | A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. | 4.3 | |
2025-02-22 | CVE-2024-13873 | Wpjobportal | Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.8 via the deleteUserPhoto() function due to missing validation on a user controlled key. | 4.3 |
2025-02-21 | CVE-2025-1543 | Iteachyou | Path Traversal vulnerability in Iteachyou Dreamer CMS 4.1.3 A vulnerability, which was classified as problematic, has been found in iteachyou Dreamer CMS 4.1.3. | 4.3 |
2025-02-21 | CVE-2024-13883 | Victorfreitas | Cross-Site Request Forgery (CSRF) vulnerability in Victorfreitas Wpupper Share Buttons The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.51. | 4.3 |
2025-02-20 | CVE-2024-49344 | IBM | Session Fixation vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application establishes a session when a user logs in and uses chat, but the chat session is still left active after logout. | 4.3 |
2025-02-20 | CVE-2024-13855 | Nilambar | Authorization Bypass Through User-Controlled Key vulnerability in Nilambar Prime Addons for Elementor The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. | 4.3 |
2025-02-20 | CVE-2024-43196 | IBM | Improper Following of a Certificate's Chain of Trust vulnerability in IBM Openpages With Watson 9.0 IBM OpenPages with Watson 8.3 and 9.0 application could allow an authenticated user to manipulate data in the Questionnaires application allowing the user to spoof other users' responses. | 4.3 |
2025-02-19 | CVE-2025-27089 | Monospace | Incorrect Authorization vulnerability in Monospace Directus Directus is a real-time API and App dashboard for managing SQL database content. | 4.3 |
2025-02-19 | CVE-2024-13336 | Exeebit | Cross-Site Request Forgery (CSRF) vulnerability in Exeebit Disable Auto Updates The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. | 4.3 |
2025-02-19 | CVE-2024-13405 | The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. | 4.3 | |
2025-02-19 | CVE-2024-13854 | Nicheaddons | Improper Access Control vulnerability in Nicheaddons Education Addon The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to missing validation on a user controlled key. | 4.3 |
2025-02-19 | CVE-2025-22622 | Age Verification for your checkout page. | 4.3 | |
2025-02-19 | CVE-2025-1447 | A vulnerability was found in kasuganosoras Pigeon 1.0.177. | 4.3 | |
2025-02-18 | CVE-2024-13783 | Ncrafts | Missing Authorization vulnerability in Ncrafts Formcraft The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in formcraft-main.php in all versions up to, and including, 3.9.11. | 4.3 |
2025-02-18 | CVE-2024-13718 | Wpdesk | Cross-Site Request Forgery (CSRF) vulnerability in Wpdesk Flexible Wishlist for Woocommerce The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. | 4.3 |
2025-02-18 | CVE-2024-13795 | Lightspeedhq | Cross-Site Request Forgery (CSRF) vulnerability in Lightspeedhq Ecwid Ecommerce Shopping Cart The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. | 4.3 |
2025-02-18 | CVE-2024-13438 | Speedsize | Cross-Site Request Forgery (CSRF) vulnerability in Speedsize Image & Video Ai-Optimizer The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. | 4.3 |
2025-02-18 | CVE-2024-13555 | 1Clickmigration | Cross-Site Request Forgery (CSRF) vulnerability in 1Clickmigration 1 Click Migration The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. | 4.3 |
2025-02-18 | CVE-2024-13687 | Webdevocean | Missing Authorization vulnerability in Webdevocean Team Builder The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_team_builder_options() function in all versions up to, and including, 1.3. | 4.3 |
2025-02-18 | CVE-2025-0796 | Kevinbrent | Cross-Site Request Forgery (CSRF) vulnerability in Kevinbrent Wprequal The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.10. | 4.3 |
2025-02-18 | CVE-2024-13740 | Metagauss | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss Profilegrid The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. | 4.3 |