CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-49305

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.1.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49304

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeManas Search with Typesense search-with-typesense allows Stored XSS.This issue affects Search with Typesense: from n/a through <= 2.0.10.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49301

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows DOM-Based XSS.This issue affects Greenshift: from n/a through <= 11.5.5.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49299

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPlugged.com WebHotelier webhotelier allows Stored XSS.This issue affects WebHotelier: from n/a through <= 1.9.2.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49298

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows Stored XSS.This issue affects Event post: from n/a through <= 5.10.1.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-49294

    Last Modified: 23 Apr 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage-scraper-post-generator allows Retrieve Embedded Sensitive Data.This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through <= 2.6.8.2.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49293

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post Generator crawlomatic-multipage-scraper-post-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crawlomatic Multisite Scraper Post Generator: from n/a through <= 2.6.8.2.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49292

    Last Modified: 23 Apr 2026

    Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder profile-builder allows Phishing.This issue affects Profile Builder: from n/a through <= 3.13.8.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49291

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This issue affects Calculated Fields Form: from n/a through <= 5.3.58.

    Published: 6 Jun 2025
    5
    Medium

    CVE-2025-49289

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in add-ons.org PDF for WPForms pdf-for-wpforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PDF for WPForms: from n/a through <= 5.5.0.

    Published: 6 Jun 2025
    8.8
    High

    CVE-2025-49288

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This issue affects Ultimate WP Mail: from n/a through <= 1.3.5.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49287

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.2.8.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49286

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder wp-table-builder allows Cross Site Request Forgery.This issue affects WP Table Builder: from n/a through <= 2.0.6.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49285

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Cross Site Request Forgery.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 3.8.0.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49284

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction wp-maintenance-mode-site-under-construction allows Cross Site Request Forgery.This issue affects WP Maintenance Mode & Site Under Construction: from n/a through <= 4.3.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49283

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant gdpr-compliant-recaptcha-for-all-forms allows Cross Site Request Forgery.This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant: from n/a through <= 4.1.1.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49273

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Cross Site Request Forgery.This issue affects WP Tools: from n/a through <= 5.24.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49272

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in sergiotrinity Trinity Audio trinity-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trinity Audio: from n/a through <= 5.20.0.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-49270

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP-CRM System: from n/a through <= 3.4.2.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49269

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter market-exporter allows Cross Site Request Forgery.This issue affects Market Exporter: from n/a through <= 2.0.22.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-49268

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Soft8Soft LLC Verge3D verge3d allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Verge3D: from n/a through <= 4.9.4.

    Published: 6 Jun 2025
    7.6
    High

    CVE-2025-49263

    Last Modified: 23 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WCVendors WC Vendors Marketplace wc-vendors allows Blind SQL Injection.This issue affects WC Vendors Marketplace: from n/a through <= 2.5.6.

    Published: 6 Jun 2025
    7.6
    High

    CVE-2025-49262

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Extension for Elementor sina-extension-for-elementor allows Stored XSS.This issue affects Sina Extension for Elementor: from n/a through <= 3.6.1.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49250

    Last Modified: 23 Apr 2026

    Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase team-showcase-cm allows Code Injection.This issue affects Team Showcase: from n/a through < 25.05.13.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49248

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in cmoreira Team Showcase team-showcase-cm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Showcase: from n/a through < 25.05.13.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49246

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in cmoreira Testimonials Showcase testimonials-showcase allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonials Showcase: from n/a through <= 1.9.16.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49244

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vova Shortcodes Ultimate shortcodes-ultimate allows Stored XSS.This issue affects Shortcodes Ultimate: from n/a through <= 7.3.5.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49243

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark ShiftNav – Responsive Mobile Menu shiftnav-responsive-mobile-menu allows Stored XSS.This issue affects ShiftNav – Responsive Mobile Menu: from n/a through <= 1.8.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49242

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark Bellows Accordion Menu bellows-accordion-menu allows Stored XSS.This issue affects Bellows Accordion Menu: from n/a through <= 1.4.3.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-49241

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in bobbingwide oik oik allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects oik: from n/a through <= 4.15.1.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49240

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in nK DocsPress docspress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DocsPress: from n/a through <= 2.5.2.

    Published: 6 Jun 2025
    5.4
    Medium

    CVE-2025-49239

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Cross Site Request Forgery.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.5.0.

    Published: 6 Jun 2025
    4.3
    Medium

    CVE-2025-49238

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request Forgery.This issue affects Everest Backup: from n/a through <= 2.3.3.

    Published: 6 Jun 2025
    7.4
    High

    CVE-2025-49237

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects POEditor: from n/a through <= 0.9.10.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-49236

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in raychat Raychat raychat allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Raychat: from n/a through <= 2.1.0.

    Published: 6 Jun 2025
    6.5
    Medium

    CVE-2025-49235

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Stored XSS.This issue affects RTMKit: from n/a through <= 1.6.0.

    Published: 6 Jun 2025
    2
    Low

    CVE-2025-5765

    Last Modified: 10 Jun 2025

    A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    2
    Low

    CVE-2025-5764

    Last Modified: 10 Jun 2025

    A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/insert_laundry.php. The manipulation of the argument Customer leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    9.8
    Critical

    CVE-2025-49072

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue affects Mr. Murphy: from n/a through < 1.2.12.1.

    Published: 6 Jun 2025
    9.8
    Critical

    CVE-2025-49073

    Last Modified: 23 Apr 2026

    Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This issue affects Sweet Dessert: from n/a through < 1.1.13.

    Published: 6 Jun 2025
    2
    Low

    CVE-2025-5763

    Last Modified: 10 Jun 2025

    A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    2.1
    Low

    CVE-2025-5762

    Last Modified: 10 Jun 2025

    A vulnerability, which was classified as critical, was found in code-projects Patient Record Management System 1.0. Affected is an unknown function of the file view_hematology.php. The manipulation of the argument itr_no leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 6 Jun 2025
    8.3
    High

    CVE-2025-41361

    Last Modified: 15 Apr 2026

    Uncontrolled resource consumption vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. The devices improperly handle TLS requests associated with PROCOME sockets, so TLS requests sent to those PROCOME ports could cause the device to reboot and result in a denial of service. To exploit this vulnerability, PROCOME ports must be configured and active, with communications encryption active.

    Published: 6 Jun 2025
    4.8
    Medium

    CVE-2025-41367

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious JavaScript payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can only be executed with permissions higher than the view permission.

    Published: 6 Jun 2025
    5.1
    Medium

    CVE-2025-41366

    Last Modified: 15 Apr 2026

    In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can only be executed with permissions higher than the view permission.

    Published: 6 Jun 2025
    5.1
    Medium

    CVE-2025-41365

    Last Modified: 15 Apr 2026

    Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed only with permissions higher than the view permission.

    Published: 6 Jun 2025
    5.1
    Medium

    CVE-2025-41364

    Last Modified: 15 Apr 2026

    Stored Cross-Site Scripting (XSS) vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious JavaScript payload in software that will run in the victim's browser. Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed with view permission.

    Published: 6 Jun 2025
    7.1
    High

    CVE-2025-48329

    Last Modified: 23 Apr 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Real Time Validation for Gravity Forms real-time-validation-for-gravity-forms allows Reflected XSS.This issue affects Real Time Validation for Gravity Forms: from n/a through <= 1.7.0.

    Published: 6 Jun 2025
    5.3
    Medium

    CVE-2025-41363

    Last Modified: 15 Apr 2026

    In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability requires authenticating to the device and executing certain commands that can be executed with view permission.

    Published: 6 Jun 2025
    8.8
    High

    CVE-2025-39358

    Last Modified: 29 Apr 2026

    Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Posts Carousel: from n/a through <= 1.3.12.

    Published: 6 Jun 2025