CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2025-6355

    Last Modified: 13 Nov 2025

    A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jun 2025
    10
    Critical

    CVE-2025-49132

    Last Modified: 15 Apr 2026

    Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.

    Published: 20 Jun 2025
    2.7
    Low

    CVE-2025-48059

    Last Modified: 15 Apr 2026

    PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criteria versions 6.3.0 to before 6.7.2 and com.powsybl:powsybl-contingency-api versions 5.0.0 to before 6.3.0, there is a a potential polynomial Regular Expression Denial of Service (ReDoS) vulnerability in the RegexCriterion class. This class compiles and evaluates an unvalidated, user-supplied regular expression against the identifier of an Identifiable object via Pattern.compile(regex).matcher(id).find(). If successfully exploited, a malicious actor can cause significant CPU exhaustion through repeated or recursive filter(...) calls — especially if performed over large network models or filtering operations. This issue has been patched in com.powsybl:powsybl-iidm-criteria 6.7.2.

    Published: 20 Jun 2025
    5.5
    Medium

    CVE-2025-6354

    Last Modified: 26 Jun 2025

    A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of the file /function/customer_signup.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jun 2025
    2
    Low

    CVE-2025-6353

    Last Modified: 11 Jul 2025

    A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument keyword leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jun 2025
    5.5
    Medium

    CVE-2025-6352

    Last Modified: 23 Oct 2025

    A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of the file /vote.php of the component Backend. The manipulation leads to direct request. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jun 2025
    2.1
    Low

    CVE-2025-6351

    Last Modified: 26 Jun 2025

    A vulnerability was found in itsourcecode Employee Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editprofile.php. The manipulation of the argument emp1name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jun 2025
    1.9
    Low

    CVE-2025-6347

    Last Modified: 11 Jul 2025

    A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This vulnerability affects unknown code of the file /responsive/resblog/blogadmin/admin/pageViewMembers.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 20 Jun 2025
    7.1
    High

    CVE-2025-49873

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Elessi elessi-theme allows Reflected XSS.This issue affects Elessi: from n/a through <= 6.3.9.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49964

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in indgeek ClipLink cliplink allows Cross Site Request Forgery.This issue affects ClipLink: from n/a through <= 1.1.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49965

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Oganro PixelBeds Channel Manager and Hotel Booking Engine pixelbeds-channel-manager-booking-engine allows Cross Site Request Forgery.This issue affects PixelBeds Channel Manager and Hotel Booking Engine: from n/a through <= 1.0.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49966

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Oganro Oganro Travel Portal Search Widget for HotelBeds APITUDE API oganro-travel-portal-search-widget-for-hotelbeds-apitude-api allows Cross Site Request Forgery.This issue affects Oganro Travel Portal Search Widget for HotelBeds APITUDE API: from n/a through <= 1.0.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49967

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in marcusjansen Live Sports Streamthunder live-sports-streamthunder allows Cross Site Request Forgery.This issue affects Live Sports Streamthunder: from n/a through <= 2.1.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49968

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Oganro XML Travel Portal Widget oganro-reservation-widget allows Cross Site Request Forgery.This issue affects XML Travel Portal Widget: from n/a through <= 2.0.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49969

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Zara 4 Zara 4 Image Compression zara-4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zara 4 Image Compression: from n/a through <= 1.2.17.2.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49970

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in sparklewpthemes Hello FSE Blog hello-fse-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hello FSE Blog: from n/a through <= 1.0.6.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49971

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eDS Responsive Menu: from n/a through <= 1.2.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49972

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in David Wood TM Replace Howdy tm-replace-howdy allows Cross Site Request Forgery.This issue affects TM Replace Howdy: from n/a through <= 1.4.2.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49973

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a through <= 1.0.10.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49974

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in upstreamplugin UpStream: a Project Management Plugin for WordPress upstream allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UpStream: a Project Management Plugin for WordPress: from n/a through <= 2.1.1.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49975

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This issue affects JobWP: from n/a through <= 2.4.0.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49976

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notifier: from n/a through <= 2.7.12.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49977

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49978

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in eyecix JobSearch wp-jobsearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through < 3.0.6.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49979

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in slui Media Hygiene media-hygiene allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Hygiene: from n/a through <= 4.0.1.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49980

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WP Event Manager WP User Profile Avatar wp-user-profile-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP User Profile Avatar: from n/a through <= 1.0.6.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49981

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in mahabub81 User Roles and Capabilities user-roles-and-capabilities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Roles and Capabilities: from n/a through <= 1.2.6.

    Published: 20 Jun 2025
    4.3
    Medium

    CVE-2025-49982

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in aguilatechnologies WP Customer Area customer-area allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Customer Area: from n/a through <= 8.3.4.

    Published: 20 Jun 2025
    4.9
    Medium

    CVE-2025-49983

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Joe Hoyle WPThumb wp-thumb allows Server Side Request Forgery.This issue affects WPThumb: from n/a through <= 0.10.

    Published: 20 Jun 2025
    4.9
    Medium

    CVE-2025-49984

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in blubrry PowerPress Podcasting powerpress allows Server Side Request Forgery.This issue affects PowerPress Podcasting: from n/a through <= 11.13.11.

    Published: 20 Jun 2025
    4.9
    Medium

    CVE-2025-49985

    Last Modified: 23 Apr 2026

    Server-Side Request Forgery (SSRF) vulnerability in Ali Irani Auto Upload Images auto-upload-images allows Server Side Request Forgery.This issue affects Auto Upload Images: from n/a through <= 3.3.2.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49986

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in thanhtungtnt Video List Manager video-list-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Video List Manager: from n/a through <= 1.7.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49987

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WPFactory CRM ERP Business Solution crm-erp-business-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CRM ERP Business Solution: from n/a through <= 1.13.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49988

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Renzo Johnson Contact Form 7 AWeber Extension integrate-contact-form-7-and-aweber allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form 7 AWeber Extension: from n/a through <= 0.1.40.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49989

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in App Cheap App Builder app-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Builder: from n/a through <= 5.5.6.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49990

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contentstudio: from n/a through <= 1.3.7.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49991

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in tggfref WP-Recall allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-Recall: from n/a through 16.26.14.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49993

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in csarturas Cookie-Script.com cookie-script-com allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cookie-Script.com: from n/a through <= 1.2.1.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49995

    Last Modified: 23 Apr 2026

    Authorization Bypass Through User-Controlled Key vulnerability in dFactory Download Attachments download-attachments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Attachments: from n/a through <= 1.3.1.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49996

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.4.

    Published: 20 Jun 2025
    5.3
    Medium

    CVE-2025-49997

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Syed Balkhi Giveaways and Contests by RafflePress rafflepress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Giveaways and Contests by RafflePress: from n/a through <= 1.12.18.

    Published: 20 Jun 2025
    5.4
    Medium

    CVE-2025-49998

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Wetail WooCommerce Fortnox Integration woocommerce-fortnox-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Fortnox Integration: from n/a through <= 4.5.5.

    Published: 20 Jun 2025
    5.4
    Medium

    CVE-2025-50008

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in cscode WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily innovs-woo-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily: from n/a through <= 1.2.4.5.

    Published: 20 Jun 2025
    5.4
    Medium

    CVE-2025-50009

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from n/a through <= 1.5.3.

    Published: 20 Jun 2025
    5.4
    Medium

    CVE-2025-50010

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Zapier Zapier for WordPress zapier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zapier for WordPress: from n/a through <= 1.5.2.

    Published: 20 Jun 2025
    5.9
    Medium

    CVE-2025-50011

    Last Modified: 28 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Félix Martínez Recipes manager - WPH allows Stored XSS. This issue affects Recipes manager - WPH: from n/a through 1.0.4.

    Published: 20 Jun 2025
    5.9
    Medium

    CVE-2025-50012

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fridaysystems Inventory Presser inventory-presser allows Stored XSS.This issue affects Inventory Presser: from n/a through <= 15.2.6.

    Published: 20 Jun 2025
    5.9
    Medium

    CVE-2025-50013

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason Judge CSV Importer Improved csv-importer-improved allows Stored XSS.This issue affects CSV Importer Improved: from n/a through <= 0.6.1.

    Published: 20 Jun 2025
    5.9
    Medium

    CVE-2025-50014

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iamapinan PDPA Consent for Thailand pdpa-consent allows Stored XSS.This issue affects PDPA Consent for Thailand: from n/a through <= 1.1.1.

    Published: 20 Jun 2025
    5.9
    Medium

    CVE-2025-50015

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rodrigo Bastos Hand Talk handtalk allows Stored XSS.This issue affects Hand Talk: from n/a through <= 6.1.

    Published: 20 Jun 2025