CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2024-11719

    Last Modified: 9 Jun 2025

    The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-11718

    Last Modified: 9 Jun 2025

    The tarteaucitron-wp WordPress plugin before 0.3.0 allows author level and above users to add HTML into a post/page, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-11502

    Last Modified: 9 Jun 2025

    The Planning Center Online Giving WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-11373

    Last Modified: 9 Jun 2025

    The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    7.2
    High

    CVE-2024-11372

    Last Modified: 9 Jun 2025

    The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    7.2
    High

    CVE-2024-11269

    Last Modified: 12 Jun 2025

    The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statement, allowing Admin to perform SQL injection attacks.

    Published: 15 May 2025
    8.8
    High

    CVE-2024-11267

    Last Modified: 12 Jun 2025

    The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-11266

    Last Modified: 12 Jun 2025

    The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-11221

    Last Modified: 12 Jun 2025

    The Full Screen (Page) Background Image Slideshow WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-11190

    Last Modified: 12 Jun 2025

    The jwp-a11y WordPress plugin through 4.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-11189

    Last Modified: 9 Jun 2025

    The Social Share And Social Locker WordPress plugin before 1.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    6.1
    Medium

    CVE-2024-11141

    Last Modified: 12 Jun 2025

    The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    3.5
    Low

    CVE-2024-11140

    Last Modified: 9 Jun 2025

    The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-11109

    Last Modified: 4 Jun 2025

    The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-10818

    Last Modified: 12 Jun 2025

    The JSFiddle Shortcode WordPress plugin before 1.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-10677

    Last Modified: 12 Jun 2025

    The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10639

    Last Modified: 12 Jun 2025

    The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.3
    Medium

    CVE-2024-10634

    Last Modified: 9 Jun 2025

    The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10632

    Last Modified: 9 Jun 2025

    The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    6.5
    Medium

    CVE-2024-10631

    Last Modified: 9 Jun 2025

    The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

    Published: 15 May 2025
    5.4
    Medium

    CVE-2024-10504

    Last Modified: 4 Jun 2025

    The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10475

    Last Modified: 9 Jun 2025

    The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10362

    Last Modified: 9 Jun 2025

    The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10149

    Last Modified: 9 Jun 2025

    The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10145

    Last Modified: 4 Jun 2025

    The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10144

    Last Modified: 4 Jun 2025

    The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10143

    Last Modified: 12 Jun 2025

    The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10107

    Last Modified: 4 Jun 2025

    The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    2.7
    Low

    CVE-2024-10098

    Last Modified: 9 Jun 2025

    The ApplyOnline WordPress plugin before 2.6.3 does not protect uploaded files during the application process, allowing unauthenticated users to access them and any private information they contain

    Published: 15 May 2025
    5.9
    Medium

    CVE-2024-10076

    Last Modified: 4 Jun 2025

    The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks

    Published: 15 May 2025
    5.6
    Medium

    CVE-2024-10075

    Last Modified: 4 Jun 2025

    The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible to authorised users, which could allow unauthenticated users to run arbitrary shortcodes and block.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2024-10054

    Last Modified: 4 Jun 2025

    The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 15 May 2025
    4.1
    Medium

    CVE-2024-10009

    Last Modified: 11 Jun 2025

    The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4705

    Last Modified: 28 May 2025

    A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file /admin/view-incomingvehicle-detail.php. The manipulation of the argument viewid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    5.5
    Medium

    CVE-2025-3440

    Last Modified: 26 Aug 2025

    IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4704

    Last Modified: 28 May 2025

    A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4703

    Last Modified: 28 May 2025

    A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    2.7
    Low

    CVE-2025-2570

    Last Modified: 6 Oct 2025

    Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have access to `ExperimentalSettings` which allows a System Manager to access `ExperimentSettings` when `RestrictSystemAdmin` is true via System Console.

    Published: 15 May 2025
    4.3
    Medium

    CVE-2025-2527

    Last Modified: 22 Aug 2025

    Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4702

    Last Modified: 28 May 2025

    A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affected is an unknown function of the file /admin/add-category.php. The manipulation of the argument catename leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    4.8
    Medium

    CVE-2025-4701

    Last Modified: 15 Apr 2026

    A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue affects the function torch.load of the file models/utils.py. The manipulation of the argument path leads to deserialization. It is possible to launch the attack on the local host.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4699

    Last Modified: 28 May 2025

    A vulnerability classified as critical was found in PHPGurukul Apartment Visitors Management System 1.0. This vulnerability affects unknown code of the file /admin/visitors-form.php. The manipulation of the argument Category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4698

    Last Modified: 28 May 2025

    A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/forget-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    5.9
    Medium

    CVE-2025-4516

    Last Modified: 22 Apr 2026

    There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.

    Published: 15 May 2025
    6.9
    Medium

    CVE-2025-4697

    Last Modified: 28 May 2025

    A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/edit-directory.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    5.3
    Medium

    CVE-2025-4696

    Last Modified: 13 Nov 2025

    A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    5.3
    Medium

    CVE-2025-4695

    Last Modified: 13 Nov 2025

    A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add-users.php. The manipulation of the argument uadd leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 15 May 2025
    2
    Low

    CVE-2025-4762

    Last Modified: 15 Apr 2026

    Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.

    Published: 15 May 2025
    9.8
    Critical

    CVE-2025-4564

    Last Modified: 22 Apr 2026

    The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation via the 'delpdf' action in all versions up to, and including, 3.18. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

    Published: 15 May 2025
    4.3
    Medium

    CVE-2025-3446

    Last Modified: 29 Sept 2025

    Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that team via the API to add a single user to a team.

    Published: 15 May 2025