CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2025-64528

    Last Modified: 20 Feb 2026

    Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when `enable_names` is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-63027

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webcreations907 WBC907 Core wbc907-core allows Stored XSS.This issue affects WBC907 Core: from n/a through <= 3.4.1.

    Published: 30 Dec 2025
    8.9
    High

    CVE-2025-15255

    Last Modified: 24 Feb 2026

    A vulnerability was determined in Tenda W6-S 1.0.0.4(510). This impacts an unknown function of the file /bin/httpd of the component R7websSsecurityHandler. Executing a manipulation of the argument Cookie can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-64190

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.6.

    Published: 30 Dec 2025
    2.1
    Low

    CVE-2025-15254

    Last Modified: 24 Feb 2026

    A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Performing a manipulation results in os command injection. The attack may be initiated remotely. The exploit has been made public and could be used.

    Published: 30 Dec 2025
    7.4
    High

    CVE-2025-15253

    Last Modified: 24 Feb 2026

    A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /goform/exeCommand. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 30 Dec 2025
    7.4
    High

    CVE-2025-15252

    Last Modified: 24 Feb 2026

    A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the file /goform/setDhcpAP. This manipulation of the argument startip/endip/leasetime/gateway/dns1/dns2 causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 30 Dec 2025
    6.3
    Medium

    CVE-2025-15251

    Last Modified: 15 Apr 2026

    A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in xml external entity reference. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The project owner replied to the issue report: "Okay, we'll handle it as soon as possible."

    Published: 30 Dec 2025
    2
    Low

    CVE-2025-15250

    Last Modified: 15 Apr 2026

    A security vulnerability has been detected in 08CMS Novel System up to 3.4. This issue affects some unknown processing of the file admina/mtpls.inc.php of the component Template Handler. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 30 Dec 2025
    5.1
    Medium

    CVE-2025-15249

    Last Modified: 15 Apr 2026

    A weakness has been identified in zhujunliang3 work_platform up to 6bc5a50bb527ce27f7906d11ea6ec139beb79c31. This vulnerability affects unknown code of the component Content Handler. Executing manipulation can lead to cross site scripting. The attack may be performed from remote. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 30 Dec 2025
    2
    Low

    CVE-2025-15248

    Last Modified: 15 Apr 2026

    A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb4639. This affects an unknown part of the component Write a Review. Performing manipulation of the argument content results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited. This product adopts a rolling release strategy to maintain continuous delivery The project was informed of the problem early through an issue report but has not responded yet.

    Published: 30 Dec 2025
    Unknown

    CVE-2023-54290

    Last Modified: 30 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-14426

    Last Modified: 20 Apr 2026

    The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'edit_rating' function in all versions up to, and including, 3.2.18. This makes it possible for authenticated attackers with Contributor-level access and above to modify or delete the rating meta on any testimonial post, including those created by other users, by reusing a valid nonce obtained from their own testimonial edit screen.

    Published: 30 Dec 2025
    Unknown

    CVE-2023-54256

    Last Modified: 30 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Dec 2025
    Unknown

    CVE-2023-54212

    Last Modified: 30 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Dec 2025
    Unknown

    CVE-2022-50831

    Last Modified: 30 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 30 Dec 2025
    5.5
    Medium

    CVE-2025-15247

    Last Modified: 24 Feb 2026

    A vulnerability was identified in gmg137 snap7-rs up to 153d3e8c16decd7271e2a5b2e3da4d6f68589424. Affected by this issue is the function snap7_rs::client::S7Client::download of the file client.rs. Such manipulation leads to heap-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 30 Dec 2025
    2.1
    Low

    CVE-2025-15246

    Last Modified: 15 Apr 2026

    A vulnerability was determined in aizuda snail-job up to 1.7.0 on macOS. Affected by this vulnerability is the function FurySerializer.deserialize of the component API. This manipulation of the argument argsStr causes deserialization. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

    Published: 30 Dec 2025
    7.2
    High

    CVE-2025-14509

    Last Modified: 21 Apr 2026

    The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.1.13. This is due to the plugin using eval() to execute user-supplied input from the 'Conditional Tags' setting without proper validation or sanitization. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP code on the server. In WordPress multisite installations, this allows Site Administrators to execute arbitrary code, a capability they should not have since plugin/theme file editing is disabled for non-Super Admins in multisite environments.

    Published: 30 Dec 2025
    2
    Low

    CVE-2025-15245

    Last Modified: 5 Jan 2026

    A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path traversal. The attack must originate from the local network. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 30 Dec 2025
    5.3
    Medium

    CVE-2025-69093

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopMagic: from n/a through <= 4.7.2.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69092

    Last Modified: 1 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.3.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69091

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69089

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in autolistings Auto Listings auto-listings allows Stored XSS.This issue affects Auto Listings: from n/a through <= 2.7.1.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69088

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vidish Combo Offers WooCommerce woo-combo-offers allows DOM-Based XSS.This issue affects Combo Offers WooCommerce: from n/a through <= 4.2.

    Published: 30 Dec 2025
    8.1
    High

    CVE-2025-69034

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Lekker lekker allows PHP Local File Inclusion.This issue affects Lekker: from n/a through <= 1.8.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69033

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.3.

    Published: 30 Dec 2025
    5.4
    Medium

    CVE-2025-69032

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes FiveStar fivestar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FiveStar: from n/a through <= 1.7.

    Published: 30 Dec 2025
    5.3
    Medium

    CVE-2025-69031

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Skywarrior Arcane arcane allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arcane: from n/a through <= 3.6.6.

    Published: 30 Dec 2025
    5.4
    Medium

    CVE-2025-69030

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3.

    Published: 30 Dec 2025
    5.4
    Medium

    CVE-2025-69029

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Select-Themes Struktur struktur allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Struktur: from n/a through <= 2.5.1.

    Published: 30 Dec 2025
    5.3
    Medium

    CVE-2025-69028

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in BoldGrid weForms weforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weForms: from n/a through <= 1.6.25.

    Published: 30 Dec 2025
    5.3
    Medium

    CVE-2025-69027

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in tychesoftwares Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through <= 3.2.0.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69026

    Last Modified: 24 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roxnor PopupKit popup-builder-block allows Retrieve Embedded Sensitive Data.This issue affects PopupKit: from n/a through <= 2.1.5.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69025

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Aethonic Poptics poptics allows Retrieve Embedded Sensitive Data.This issue affects Poptics: from n/a through <= 1.0.20.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69024

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in bizswoop BizPrint print-google-cloud-print-gcp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BizPrint: from n/a through <= 4.6.7.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69023

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Marketing Fire Discussion Board wp-discussion-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Discussion Board: from n/a through <= 2.5.7.

    Published: 30 Dec 2025
    5.4
    Medium

    CVE-2025-69022

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Weblizar - WordPress Themes & Plugin HR Management Lite hr-management-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HR Management Lite: from n/a through <= 3.6.

    Published: 30 Dec 2025
    5.4
    Medium

    CVE-2025-69021

    Last Modified: 24 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: from n/a through <= 6.0.7.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69020

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Stored XSS.This issue affects Newsletters: from n/a through <= 4.12.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69019

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FlippingBook FlippingBook flippingbook allows DOM-Based XSS.This issue affects FlippingBook: from n/a through <= 2.0.1.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69018

    Last Modified: 15 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows DOM-Based XSS.This issue affects Web Directory Free: from n/a through <= 1.7.12.

    Published: 30 Dec 2025
    6.5
    Medium

    CVE-2025-69017

    Last Modified: 24 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Stored XSS.This issue affects RestroPress: from n/a through <= 3.2.8.6.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69016

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in averta Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through <= 2.17.15.

    Published: 30 Dec 2025
    3.8
    Low

    CVE-2025-69015

    Last Modified: 24 Apr 2026

    Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: from n/a through <= 1.7.2.

    Published: 30 Dec 2025
    4.9
    Medium

    CVE-2025-69014

    Last Modified: 24 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.7.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69013

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in jetmonsters Stratum stratum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stratum: from n/a through <= 1.6.1.

    Published: 30 Dec 2025
    4.3
    Medium

    CVE-2025-69012

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Stephen Harris Event Organiser event-organiser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Organiser: from n/a through <= 3.12.8.

    Published: 30 Dec 2025
    5.3
    Medium

    CVE-2025-69010

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in themebeez Themebeez Toolkit themebeez-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Themebeez Toolkit: from n/a through <= 1.3.5.

    Published: 30 Dec 2025
    5.3
    Medium

    CVE-2025-69009

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in kamleshyadav Medicalequipment medicalequipment allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Medicalequipment: from n/a through <= 1.0.9.

    Published: 30 Dec 2025