CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2025-58622

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in yydevelopment Mobile Contact Line mobile-contact-line allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile Contact Line: from n/a through <= 2.4.0.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58621

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amuse Labs PuzzleMe for WordPress puzzleme allows Stored XSS.This issue affects PuzzleMe for WordPress: from n/a through <= 1.2.0.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58620

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Stored XSS.This issue affects PDF for WPForms: from n/a through <= 6.2.1.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58618

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Jernigan Pie Calendar pie-calendar allows DOM-Based XSS.This issue affects Pie Calendar: from n/a through <= 1.2.8.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-58617

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in FAKTOR VIER F4 Media Taxonomies f4-media-taxonomies allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects F4 Media Taxonomies: from n/a through <= 1.1.4.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58616

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Frisbii Frisbii Pay reepay-checkout-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frisbii Pay: from n/a through <= 1.8.2.1.

    Published: 3 Sept 2025
    4.4
    Medium

    CVE-2025-58615

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in gfazioli WP Bannerize Pro wp-bannerize-pro allows Server Side Request Forgery.This issue affects WP Bannerize Pro: from n/a through <= 1.10.0.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58614

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jamel.Z Tooltipy bluet-keywords-tooltip-generator allows Stored XSS.This issue affects Tooltipy: from n/a through <= 5.5.6.

    Published: 3 Sept 2025
    5.3
    Medium

    CVE-2025-58613

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Barn2 Plugins Posts Table with Search & Sort posts-data-table allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Posts Table with Search & Sort: from n/a through <= 1.4.10.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58612

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-58611

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tickera Tickera tickera-event-ticketing-system allows Cross Site Request Forgery.This issue affects Tickera: from n/a through <= 3.5.5.6.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58610

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Gallery PhotoBlocks photoblocks-grid-gallery allows Stored XSS.This issue affects Gallery PhotoBlocks: from n/a through <= 1.3.1.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58609

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Stored XSS.This issue affects Latest Post Shortcode: from n/a through <= 14.0.3.

    Published: 3 Sept 2025
    7.5
    High

    CVE-2025-58608

    Last Modified: 23 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuddyDev MediaPress mediapress allows PHP Local File Inclusion.This issue affects MediaPress: from n/a through <= 1.5.9.1.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58607

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice & Consent Banner for GDPR & CCPA Compliance: from n/a through <= 1.7.11.

    Published: 3 Sept 2025
    5
    Medium

    CVE-2025-58606

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SaasLauncher: from n/a through <= 1.3.0.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58605

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affects WP Delicious: from n/a through <= 1.8.7.

    Published: 3 Sept 2025
    7.6
    High

    CVE-2025-58604

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint mail-mint allows SQL Injection.This issue affects Mail Mint: from n/a through <= 1.18.5.

    Published: 3 Sept 2025
    5.3
    Medium

    CVE-2025-58603

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Surfer: from n/a through <= 1.6.4.574.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58602

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Content If-So Dynamic Content Personalization if-so allows Stored XSS.This issue affects If-So Dynamic Content Personalization: from n/a through <= 1.9.4.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-58601

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Classified Listing: from n/a through <= 5.0.6.

    Published: 3 Sept 2025
    5.3
    Medium

    CVE-2025-58600

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.9.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-58599

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.1.0.

    Published: 3 Sept 2025
    6.6
    Medium

    CVE-2025-58598

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce klarna-order-management-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Klarna Order Management for WooCommerce: from n/a through <= 1.9.8.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-58597

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpForo Forum: from n/a through <= 2.4.6.

    Published: 3 Sept 2025
    5.9
    Medium

    CVE-2025-58596

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction MailOptin mailoptin allows Stored XSS.This issue affects MailOptin: from n/a through <= 1.2.75.0.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-58594

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy: from n/a through <= 2.7.12.

    Published: 3 Sept 2025
    6.5
    Medium

    CVE-2025-58593

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fox by ThemeIsle themeisle-companion allows Stored XSS.This issue affects Orbit Fox by ThemeIsle: from n/a through <= 3.0.0.

    Published: 3 Sept 2025
    4.8
    Medium

    CVE-2025-9823

    Last Modified: 15 Apr 2026

    SummaryA Cross-Site Scripting (XSS) vulnerability allows an attacker to execute arbitrary JavaScript in the context of another user’s session. This occurs because user-supplied input is reflected back in the server’s response without proper sanitization or escaping, potentially enabling malicious actions such as session hijacking, credential theft, or unauthorized actions in the application. DetailsThe vulnerability resides in the “Tags” input field on the /s/ajax?action=lead:addLeadTags endpoint. Although the server applies sanitization before storing the data or returning it later, the payload is executed immediately in the victim’s browser upon reflection, allowing an attacker to run arbitrary JavaScript in the user’s session. ImpactA Reflected XSS attack can have a significant impact, allowing attackers to steal sensitive user data like cookies, redirect users to malicious websites, manipulate the web page content, and essentially take control of a user's session within an application by executing malicious JavaScript code within the victim's browser, even if the server-side code is secure; essentially enabling them to perform actions as if they were the logged-in user. References * Web Security Academy: Cross-site scripting https://portswigger.net/web-security/cross-site-scripting * Web Security Academy: Reflected cross-site scripting https://portswigger.net/web-security/cross-site-scripting/reflected

    Published: 3 Sept 2025
    5.9
    Medium

    CVE-2025-9824

    Last Modified: 15 Apr 2026

    ImpactThe attacker can validate if a user exists by checking the time login returns. This timing difference can be used to enumerate valid usernames, after which an attacker could attempt brute force attacks. PatchesThis vulnerability has been patched, implementing a timing-safe form login authenticator that ensures consistent response times regardless of whether a user exists or not. Technical DetailsThe vulnerability was caused by different response times when: * A valid username was provided (password hashing occurred) * An invalid username was provided (no password hashing occurred) The fix introduces a TimingSafeFormLoginAuthenticator that performs a dummy password hash verification even for non-existent users, ensuring consistent timing. WorkaroundsNo workarounds are available. Users should upgrade to the patched version. References * https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/03-Identity_Management_Testing/04-Testing_for_Account_Enumeration_and_Guessable_User_Account

    Published: 3 Sept 2025
    5.5
    Medium

    CVE-2025-9822

    Last Modified: 15 Apr 2026

    SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usually does not have access to certain parameters, such as database credentials, can disclose them.

    Published: 3 Sept 2025
    8.6
    High

    CVE-2025-47421

    Last Modified: 15 Apr 2026

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH login string can lead a valid administrator user to gain Privileged Operating System access on the device. Following Products Models are affected: TSW-x70 TSW-x60 TST-1080 AM-3000/3100/3200 Soundbar VB70 HD-PS622/621/402 HD-TXU-RXU-4kZ-211 HD-MDNXM-4KZ-E *Note: additional firmware updates will be published once made available

    Published: 3 Sept 2025
    8.6
    High

    CVE-2025-2416

    Last Modified: 6 Jun 2026

    Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass. This issue affects LimonDesk: from s1.02.14 before v1.02.17.

    Published: 3 Sept 2025
    4.7
    Medium

    CVE-2025-0878

    Last Modified: 6 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS). This issue affects LimonDesk: from s1.02.14 before v1.02.17.

    Published: 3 Sept 2025
    7.3
    High

    CVE-2024-13068

    Last Modified: 1 Jun 2026

    Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: from s1.02.14 before v1.02.17.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2024-13066

    Last Modified: 1 Jun 2026

    Improper Restriction of Rendered UI Layers or Frames vulnerability in Akinsoft LimonDesk allows iFrame Overlay, CAPEC - 103 - Clickjacking. This issue affects LimonDesk: from s1.02.14 before v1.02.17.

    Published: 3 Sept 2025
    4.3
    Medium

    CVE-2025-3701

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Malcure Malware Scanner: from n/a through <= 16.8.

    Published: 3 Sept 2025
    8.8
    High

    CVE-2025-53691

    Last Modified: 8 Sept 2025

    Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.

    Published: 3 Sept 2025
    9.8
    Critical

    CVE-2025-53693

    Last Modified: 8 Sept 2025

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.

    Published: 3 Sept 2025
    7.5
    High

    CVE-2025-53694

    Last Modified: 8 Sept 2025

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58698

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58699

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58700

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58701

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58695

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58696

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58697

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    Unknown

    CVE-2025-58694

    Last Modified: 4 Sept 2025

    Not used

    Published: 3 Sept 2025
    2.1
    Low

    CVE-2025-41000

    Last Modified: 15 Apr 2026

    Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends entirely on the browser chosen by the user, so it is perceived as a minor threat to web application security. This vulnerability only works in older browsers.

    Published: 3 Sept 2025
    2.7
    Low

    CVE-2025-9821

    Last Modified: 15 Apr 2026

    SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request response is also disclosed DetailsWhen sending webhooks, the destination is not validated, causing SSRF. ImpactBypass of firewalls to interact with internal services. See https://owasp.org/Top10/A10_2021-Server-Side_Request_Forgery_%28SSRF%29/  for more potential impact. Resources https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html  for more information on SSRF and its fix.

    Published: 3 Sept 2025