CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2025-47275

    Last Modified: 15 Apr 2026

    Auth0-PHP provides the PHP SDK for Auth0 Authentication and Management APIs. Starting in version 8.0.0-BETA1 and prior to version 8.14.0, session cookies of applications using the Auth0-PHP SDK configured with CookieStore have authentication tags that can be brute forced, which may result in unauthorized access. Certain pre-conditions are required to be vulnerable to this issue: Applications using the Auth0-PHP SDK, or the Auth0/symfony, Auth0/laravel-auth0, and Auth0/wordpress SDKs that rely on the Auth0-PHP SDK; and session storage configured with CookieStore. Upgrade Auth0/Auth0-PHP to v8.14.0 to receive a patch. As an additional precautionary measure, rotating cookie encryption keys is recommended. Note that once updated, any previous session cookies will be rejected.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4721

    Last Modified: 27 May 2025

    A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /drive.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    5.3
    Medium

    CVE-2025-4720

    Last Modified: 27 May 2025

    A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file academic/core/drop_student.php. The manipulation of the argument img leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4719

    Last Modified: 28 May 2025

    A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4718

    Last Modified: 28 May 2025

    A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/customer_add.php. The manipulation of the argument last leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

    Published: 15 May 2025
    2.1
    Low

    CVE-2025-47929

    Last Modified: 15 Apr 2026

    DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior to commit db27b25372eb9071e63583d8faed2111a2b79f1b. A user could be tricked into uploading a file with a malicious payload. Commit db27b25372eb9071e63583d8faed2111a2b79f1b fixes the vulnerability.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2025-1138

    Last Modified: 28 Aug 2025

    IBM InfoSphere Information Server 11.7 could disclose sensitive information to an authenticated user that could aid in further attacks against the system through a directory listing.

    Published: 15 May 2025
    Unknown

    CVE-2025-4801

    Last Modified: 10 Jun 2025

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 15 May 2025
    9.1
    Critical

    CVE-2025-47928

    Last Modified: 15 Apr 2026

    Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` followed by the checking out the head.sha of a forked PR can be exploited by attackers, since untrusted code can be executed having full access to secrets (from the base repo). By exploiting the vulnerability is possible to exfiltrate `GITHUB_TOKEN` and secrets `SPOTIPY_CLIENT_ID`, `SPOTIPY_CLIENT_SECRET`. In particular `GITHUB_TOKEN` which can be used to completely overtake the repo since the token has content write privileges. The `pull_request_target` in GitHub Actions is a major security concern—especially in public repositories—because it executes untrusted code from a PR, but with the context of the base repository, including access to its secrets. Commit 9dfb7177b8d7bb98a5a6014f8e6436812a47576f reverted the change that caused the issue.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-8009

    Last Modified: 13 Nov 2025

    The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-6711

    Last Modified: 13 Nov 2025

    The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks

    Published: 15 May 2025
    6.4
    Medium

    CVE-2024-4665

    Last Modified: 13 Nov 2025

    The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce.

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-4091

    Last Modified: 13 Nov 2025

    The Responsive Gallery Grid WordPress plugin before 2.3.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-4004

    Last Modified: 13 Nov 2025

    The Advanced Cron Manager WordPress plugin before 2.5.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-4002

    Last Modified: 13 Nov 2025

    The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-3996

    Last Modified: 13 Nov 2025

    The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    6.8
    Medium

    CVE-2024-3901

    Last Modified: 13 Nov 2025

    The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-3062

    Last Modified: 10 Jun 2025

    The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-2869

    Last Modified: 5 Jun 2025

    The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-2643

    Last Modified: 11 Jun 2025

    The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-12767

    Last Modified: 13 Nov 2025

    The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts

    Published: 15 May 2025
    5.3
    Medium

    CVE-2024-0970

    Last Modified: 13 Nov 2025

    This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value.

    Published: 15 May 2025
    8.8
    High

    CVE-2024-0852

    Last Modified: 13 Nov 2025

    The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

    Published: 15 May 2025
    7.1
    High

    CVE-2024-0249

    Last Modified: 13 Nov 2025

    The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admins.

    Published: 15 May 2025
    3.5
    Low

    CVE-2023-7297

    Last Modified: 13 Nov 2025

    The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    7.5
    High

    CVE-2023-7239

    Last Modified: 9 Jun 2025

    The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.

    Published: 15 May 2025
    7.3
    High

    CVE-2023-7231

    Last Modified: 6 Jun 2025

    The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to delete links.

    Published: 15 May 2025
    6.1
    Medium

    CVE-2023-7230

    Last Modified: 27 May 2025

    The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.

    Published: 15 May 2025
    5.5
    Medium

    CVE-2023-7229

    Last Modified: 27 May 2025

    The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

    Published: 15 May 2025
    6.1
    Medium

    CVE-2023-7228

    Last Modified: 28 May 2025

    The illi Link Party! WordPress plugin through 1.0 does not sanitise and escape some parameters, which could allow unauthenticated vistors to perform Cross-Site Scripting attacks.

    Published: 15 May 2025
    7.1
    High

    CVE-2023-7197

    Last Modified: 11 Jun 2025

    The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

    Published: 15 May 2025
    4.3
    Medium

    CVE-2023-7196

    Last Modified: 11 Jun 2025

    The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.3
    Medium

    CVE-2023-7195

    Last Modified: 11 Jun 2025

    The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.

    Published: 15 May 2025
    7.1
    High

    CVE-2023-7174

    Last Modified: 11 Jun 2025

    The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2023-7168

    Last Modified: 9 Jun 2025

    The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2023-7088

    Last Modified: 12 Jun 2025

    The Add SVG Support for Media Uploader | inventivo WordPress plugin through 1.0.5 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2023-7086

    Last Modified: 12 Jun 2025

    The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 15 May 2025
    6.1
    Medium

    CVE-2023-6786

    Last Modified: 1 Aug 2025

    The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

    Published: 15 May 2025
    4.8
    Medium

    CVE-2023-6783

    Last Modified: 11 Jun 2025

    The WolfNet IDX for WordPress plugin through 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    6.1
    Medium

    CVE-2023-6541

    Last Modified: 11 Jun 2025

    The Allow SVG WordPress plugin before 1.2.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2023-6030

    Last Modified: 11 Jun 2025

    The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker

    Published: 15 May 2025
    7.3
    High

    CVE-2023-5934

    Last Modified: 4 Jun 2025

    The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2023-5932

    Last Modified: 4 Jun 2025

    The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

    Published: 15 May 2025
    4.8
    Medium

    CVE-2023-5529

    Last Modified: 4 Jun 2025

    The Advanced Page Visit Counter WordPress plugin before 8.0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    5.4
    Medium

    CVE-2023-2334

    Last Modified: 11 Jun 2025

    The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

    Published: 15 May 2025
    5.4
    Medium

    CVE-2025-2248

    Last Modified: 4 Jun 2025

    The WP-PManager WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    5.4
    Medium

    CVE-2025-2247

    Last Modified: 4 Jun 2025

    The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    6.1
    Medium

    CVE-2025-2203

    Last Modified: 12 Jun 2025

    The FunnelKit WordPress plugin before 3.10.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    5.4
    Medium

    CVE-2025-1454

    Last Modified: 12 Jun 2025

    The Ninja Pages WordPress plugin through 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2025-1303

    Last Modified: 1 Aug 2025

    The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.

    Published: 15 May 2025