CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2025-26854

    Last Modified: 15 Apr 2026

    A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

    Published: 18 Jul 2025
    7.5
    High

    CVE-2025-7438

    Last Modified: 22 Apr 2026

    The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'install_and_activate_plugin' function in all versions up to, and including, 4.7.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability is difficult to exploit due to timing requirements and environmental factors.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-7772

    Last Modified: 22 Apr 2026

    The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 16.8 via the wpmr_inspect_file() function due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

    Published: 18 Jul 2025
    5.3
    Medium

    CVE-2025-5811

    Last Modified: 20 Apr 2026

    The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Init() function in all versions up to, and including, 2.7. This makes it possible for unauthenticated attackers to delete arbitrary transient values on the WordPress site.

    Published: 18 Jul 2025
    6.4
    Medium

    CVE-2025-5800

    Last Modified: 20 Apr 2026

    The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jul 2025
    6.4
    Medium

    CVE-2025-5752

    Last Modified: 21 Apr 2026

    The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-6717

    Last Modified: 20 Apr 2026

    The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.2.56 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 18 Jul 2025
    6.4
    Medium

    CVE-2025-5767

    Last Modified: 21 Apr 2026

    The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ parameter in all versions up to, and including, 3.1.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jul 2025
    4.4
    Medium

    CVE-2025-6719

    Last Modified: 20 Apr 2026

    The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 18 Jul 2025
    4.3
    Medium

    CVE-2025-6726

    Last Modified: 21 Apr 2026

    The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the classic_gallery_slider_options() function in all versions up to, and including, 1.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update limited post meta for arbitrary posts.

    Published: 18 Jul 2025
    9.1
    Critical

    CVE-2025-7643

    Last Modified: 22 Apr 2026

    The Attachment Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handle_actions() function in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 18 Jul 2025
    6.4
    Medium

    CVE-2025-5754

    Last Modified: 21 Apr 2026

    The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jul 2025
    8.8
    High

    CVE-2025-6718

    Last Modified: 21 Apr 2026

    The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX action in all versions up to, and including, 2.2.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute and run arbitrary SQL commands.

    Published: 18 Jul 2025
    9.8
    Critical

    CVE-2025-6222

    Last Modified: 21 Apr 2026

    The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ced_rnx_order_exchange_attach_files' function in all versions up to, and including, 3.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

    Published: 18 Jul 2025
    4.3
    Medium

    CVE-2025-6781

    Last Modified: 20 Apr 2026

    The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the 'copymatic-menu' page. This makes it possible for unauthenticated attackers to update the copymatic_apikey option via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 18 Jul 2025
    6.1
    Medium

    CVE-2025-6053

    Last Modified: 20 Apr 2026

    The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the 'zuppler-online-ordering-options' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 18 Jul 2025
    6.4
    Medium

    CVE-2025-7660

    Last Modified: 21 Apr 2026

    The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_locations' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jul 2025
    4.9
    Medium

    CVE-2025-7638

    Last Modified: 21 Apr 2026

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the `order_by` parameter in all versions up to, and including, 1.45.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 18 Jul 2025
    4.3
    Medium

    CVE-2025-5816

    Last Modified: 21 Apr 2026

    The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.0 via the get_order_detail() due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's orders.

    Published: 18 Jul 2025
    8.8
    High

    CVE-2025-6813

    Last Modified: 15 Apr 2026

    The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within the auto_login() function in versions 1.0 to 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass all role checks and gain full admin privileges.

    Published: 18 Jul 2025
    8.8
    High

    CVE-2025-3740

    Last Modified: 21 Apr 2026

    The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 93.1.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The Local File Inclusion exploit can be chained to include various dashboard view files in the plugin. One such chain can be leveraged to update the password of Super Administrator accounts in Multisite environments making privilege escalation possible. The vendor has updated the version numbers beginning with `1.93.1 (02-07-2025)` for the patched version. This version comes after version 93.1.0.

    Published: 18 Jul 2025
    6.4
    Medium

    CVE-2025-7648

    Last Modified: 22 Apr 2026

    The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_button' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 18 Jul 2025
    4.4
    Medium

    CVE-2025-7431

    Last Modified: 20 Apr 2026

    The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published: 18 Jul 2025
    2
    Low

    CVE-2025-7767

    Last Modified: 29 Jul 2025

    A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/edit-art-medium-detail.php. The manipulation of the argument artmed leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 18 Jul 2025
    8.2
    High

    CVE-2025-52164

    Last Modified: 15 Apr 2026

    Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-46000

    Last Modified: 14 Oct 2025

    An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.

    Published: 18 Jul 2025
    4
    Medium

    CVE-2025-54310

    Last Modified: 9 Oct 2025

    qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

    Published: 18 Jul 2025
    9.8
    Critical

    CVE-2025-46001

    Last Modified: 14 Oct 2025

    An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-52163

    Last Modified: 15 Apr 2026

    A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows attackers to forcefully initiate connections to arbitrary internal and external resources via a crafted request. This can lead to sensitive data exposure.

    Published: 18 Jul 2025
    7.5
    High

    CVE-2025-50708

    Last Modified: 15 Apr 2026

    An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token component in the shared chat URL

    Published: 18 Jul 2025
    9
    Critical

    CVE-2025-54309

    Last Modified: 5 Nov 2025

    CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025.

    Published: 18 Jul 2025
    7.8
    High

    CVE-2025-38349

    Last Modified: 24 Jul 2026

    In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points out that epoll is decrementing the ep refcount and then doing a mutex_unlock(&ep->mtx); afterwards. That's very wrong, because it can lead to a use-after-free. That pattern is actually fine for the very last reference, because the code in question will delay the actual call to "ep_free(ep)" until after it has unlocked the mutex. But it's wrong for the much subtler "next to last" case when somebody *else* may also be dropping their reference and free the ep while we're still using the mutex. Note that this is true even if that other user is also using the same ep mutex: mutexes, unlike spinlocks, can not be used for object ownership, even if they guarantee mutual exclusion. A mutex "unlock" operation is not atomic, and as one user is still accessing the mutex as part of unlocking it, another user can come in and get the now released mutex and free the data structure while the first user is still cleaning up. See our mutex documentation in Documentation/locking/mutex-design.rst, in particular the section [1] about semantics: "mutex_unlock() may access the mutex structure even after it has internally released the lock already - so it's not safe for another context to acquire the mutex and assume that the mutex_unlock() context is not using the structure anymore" So if we drop our ep ref before the mutex unlock, but we weren't the last one, we may then unlock the mutex, another user comes in, drops _their_ reference and releases the 'ep' as it now has no users - all while the mutex_unlock() is still accessing it. Fix this by simply moving the ep refcount dropping to outside the mutex: the refcount itself is atomic, and doesn't need mutex protection (that's the whole _point_ of refcounts: unlike mutexes, they are inherently about object lifetimes).

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-7784

    Last Modified: 6 May 2026

    A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege enforcement. This vulnerability allows unauthorized elevation of access rights, compromising the intended separation of administrative duties and posing a security risk to the realm.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-52162

    Last Modified: 15 Apr 2026

    agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vulnerability allows attackers to access sensitive data via providing a crafted XML input.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-45157

    Last Modified: 17 Oct 2025

    Insecure permissions in Splashin iOS v2.0 allow unauthorized attackers to access location data for specific users.

    Published: 18 Jul 2025
    5.3
    Medium

    CVE-2025-45156

    Last Modified: 17 Oct 2025

    Splashin iOS v2.0 fails to enforce server-side interval restrictions for location updates for free-tier users.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-46002

    Last Modified: 14 Oct 2025

    An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.

    Published: 18 Jul 2025
    8.8
    High

    CVE-2025-50585

    Last Modified: 9 Sept 2025

    StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-50586

    Last Modified: 9 Sept 2025

    StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

    Published: 18 Jul 2025
    4.8
    Medium

    CVE-2025-50582

    Last Modified: 9 Sept 2025

    StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.

    Published: 18 Jul 2025
    4.8
    Medium

    CVE-2025-50583

    Last Modified: 9 Sept 2025

    StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.

    Published: 18 Jul 2025
    4.8
    Medium

    CVE-2025-50584

    Last Modified: 9 Sept 2025

    StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.

    Published: 18 Jul 2025
    4.8
    Medium

    CVE-2025-50581

    Last Modified: 23 Sept 2025

    MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-52166

    Last Modified: 15 Apr 2026

    Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate privileges to Administrator and access sensitive components and information.

    Published: 18 Jul 2025
    6.5
    Medium

    CVE-2025-52168

    Last Modified: 15 Apr 2026

    Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 allows unauthenticated attackers to access arbitrary files on the system.

    Published: 18 Jul 2025
    7.1
    High

    CVE-2025-52169

    Last Modified: 15 Apr 2026

    agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.

    Published: 18 Jul 2025
    8.7
    High

    CVE-2025-6185

    Last Modified: 15 Apr 2026

    Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious payload in URL parameters, which would execute in a client browser when accessed by a user, steal session tokens, and control the service.

    Published: 17 Jul 2025
    5.5
    Medium

    CVE-2025-7765

    Last Modified: 29 Jul 2025

    A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/addmanagerclinic.php. The manipulation of the argument clinic leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 17 Jul 2025
    5.5
    Medium

    CVE-2025-7764

    Last Modified: 29 Jul 2025

    A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected is an unknown function of the file /admin/deletedoctorclinic.php. The manipulation of the argument clinic leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 17 Jul 2025
    2.1
    Low

    CVE-2025-7763

    Last Modified: 25 Aug 2025

    A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select of the file src/main/java/com/jeesite/modules/cms/web/SiteController.java of the component Site Controller. The manipulation of the argument redirect leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 3d06b8d009d0267f0255acc87ea19d29d07cedc3. It is recommended to apply a patch to fix this issue.

    Published: 17 Jul 2025