CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2024-13776

    Last Modified: 8 Apr 2026

    The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 'seen' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration. There are several other functions also vulnerable to missing authorization.

    Published: 5 Apr 2025
    8.8
    High

    CVE-2025-2933

    Last Modified: 20 Apr 2026

    The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site. CVE-2025-26741 is likely a duplicate of this issue.

    Published: 5 Apr 2025
    6.4
    Medium

    CVE-2025-2544

    Last Modified: 21 Apr 2026

    The AI Content Pipelines plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

    Published: 5 Apr 2025
    7.5
    High

    CVE-2024-13604

    Last Modified: 15 Apr 2026

    The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/kbs directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 1.7.3.2.

    Published: 5 Apr 2025
    7.5
    High

    CVE-2025-0810

    Last Modified: 21 Apr 2026

    The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.7. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it possible for unauthenticated attackers to include and execute arbitrary PHP files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published: 5 Apr 2025
    5.5
    Medium

    CVE-2025-1500

    Last Modified: 1 Sept 2025

    IBM Maximo Application Suite 9.0 could allow an authenticated user to upload a file with dangerous types that could be executed by another user if opened.

    Published: 5 Apr 2025
    4.8
    Medium

    CVE-2025-32366

    Last Modified: 15 Apr 2026

    In ConnMan through 1.44, parse_rr in dnsproxy.c has a memcpy length that depends on an RR RDLENGTH value, i.e., *rdlen=ntohs(rr->rdlen) and memcpy(response+offset,*end,*rdlen) without a check for whether the sum of *end and *rdlen exceeds max. Consequently, *rdlen may be larger than the amount of remaining packet data in the current state of parsing. Values of stack memory locations may be sent over the network in a response.

    Published: 5 Apr 2025
    10
    Critical

    CVE-2021-47667

    Last Modified: 15 Apr 2026

    An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.

    Published: 5 Apr 2025
    4
    Medium

    CVE-2025-32358

    Last Modified: 15 Apr 2025

    In Zammad 6.4.x before 6.4.2, SSRF can occur. Authenticated admin users can enable webhooks in Zammad, which are triggered as POST requests when certain conditions are met. If a webhook endpoint returned a redirect response, Zammad would follow it automatically with another GET request. This could be abused by an attacker to cause GET requests for example in the local network.

    Published: 5 Apr 2025
    4
    Medium

    CVE-2025-32364

    Last Modified: 3 Nov 2025

    A floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling malformed inputs associated with INT_MIN.

    Published: 5 Apr 2025
    4.8
    Medium

    CVE-2025-32352

    Last Modified: 15 Apr 2026

    A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

    Published: 5 Apr 2025
    4.3
    Medium

    CVE-2025-32357

    Last Modified: 15 Apr 2025

    In Zammad 6.4.x before 6.4.2, an authenticated agent with knowledge base permissions was able to use the Zammad API to fetch knowledge base content that they have no permission for.

    Published: 5 Apr 2025
    4
    Medium

    CVE-2025-32365

    Last Modified: 3 Nov 2025

    Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

    Published: 5 Apr 2025
    4.8
    Medium

    CVE-2025-32359

    Last Modified: 15 Apr 2025

    In Zammad 6.4.x before 6.4.2, there is client-side enforcement of server-side security. When changing their two factor authentication configuration, users need to re-authenticate with their current password first. However, this change was enforced in Zammad only on the front end level, and not when using the API directly.

    Published: 5 Apr 2025
    4.2
    Medium

    CVE-2025-32360

    Last Modified: 15 Apr 2025

    In Zammad 6.4.x before 6.4.2, there is information exposure. Only agents should be able to see and work on shared article drafts. However, a logged in customer was able to see details about shared drafts for their customer tickets in the browser console, which may contain confidential information, and also to manipulate them via API.

    Published: 5 Apr 2025
    6.4
    Medium

    CVE-2025-2889

    Last Modified: 22 Apr 2026

    The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 4 Apr 2025
    6.9
    Medium

    CVE-2025-3268

    Last Modified: 23 Apr 2025

    A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    3.7
    Low

    CVE-2025-3416

    Last Modified: 30 Jun 2026

    A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.

    Published: 4 Apr 2025
    5.3
    Medium

    CVE-2025-3267

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    6.9
    Medium

    CVE-2025-3266

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this issue is some unknown functionality of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    6.9
    Medium

    CVE-2025-3265

    Last Modified: 7 Apr 2025

    A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-category.php. The manipulation of the argument Category leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    9.2
    Critical

    CVE-2024-11235

    Last Modified: 26 Feb 2026

    In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use-after-free vulnerability. If the third party can control the memory layout leading to this, for example by supplying specially crafted inputs to the script, it could lead to remote code execution.

    Published: 4 Apr 2025
    8.7
    High

    CVE-2025-3259

    Last Modified: 7 Apr 2025

    A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    6.9
    Medium

    CVE-2025-3258

    Last Modified: 28 May 2025

    A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    5.3
    Medium

    CVE-2025-3257

    Last Modified: 9 Oct 2025

    A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    5.3
    Medium

    CVE-2025-3256

    Last Modified: 9 Oct 2025

    A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    5.3
    Medium

    CVE-2025-3255

    Last Modified: 9 Oct 2025

    A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    5.3
    Medium

    CVE-2025-3254

    Last Modified: 9 Oct 2025

    A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. The manipulation of the argument description leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

    Published: 4 Apr 2025
    5.4
    Medium

    CVE-2025-32178

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 6Storage Rentals: from n/a through <= 2.20.2.

    Published: 4 Apr 2025
    5.4
    Medium

    CVE-2025-32250

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rollbar Rollbar rollbar allows Cross Site Request Forgery.This issue affects Rollbar: from n/a through <= 2.7.1.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32239

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Joao Romao Social Share Buttons & Analytics Plugin – GetSocial.io wp-share-buttons-analytics-by-getsocial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Buttons & Analytics Plugin – GetSocial.io: from n/a through <= 4.5.

    Published: 4 Apr 2025
    5.4
    Medium

    CVE-2025-32224

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Shivam Mani Tripathi Privyr CRM Integration privy-crm-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Privyr CRM Integration: from n/a through <= 1.0.2.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32280

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32278

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wprio Table Block by RioVizual riovizual allows Cross Site Request Forgery.This issue affects Table Block by RioVizual: from n/a through <= 2.3.1.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32277

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RepairBuddy: from n/a through <= 3.8213.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32276

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z administrator-z allows Cross Site Request Forgery.This issue affects Administrator Z: from n/a through <= 2026.03.02.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32274

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in axew3 WP w3all phpBB wp-w3all-phpbb-integration allows Cross Site Request Forgery.This issue affects WP w3all phpBB: from n/a through <= 2.9.8.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32273

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in freetobook Freetobook Responsive Widget freetobook-responsive-widget allows Cross Site Request Forgery.This issue affects Freetobook Responsive Widget: from n/a through <= 1.1.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32272

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Wishlist wishlist allows Cross Site Request Forgery.This issue affects Wishlist: from n/a through <= 1.0.46.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32271

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Role Pricing woocommerce-role-pricing allows Cross Site Request Forgery.This issue affects Woocommerce Role Pricing: from n/a through <= 3.5.6.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32270

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Broadstreet Broadstreet Ads broadstreet allows Cross Site Request Forgery.This issue affects Broadstreet Ads: from n/a through <= 1.52.1.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32269

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms cf7-zendesk allows Cross Site Request Forgery.This issue affects WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: from n/a through <= 1.1.3.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32268

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in www.15.to QR Code Tag for WC qr-code-tag-for-wc-from-goaskle-com allows Cross Site Request Forgery.This issue affects QR Code Tag for WC: from n/a through <= 1.9.42.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32267

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wpzinc Post to Social Media – WordPress to Hootsuite wp-to-hootsuite allows Cross Site Request Forgery.This issue affects Post to Social Media – WordPress to Hootsuite: from n/a through <= 1.5.8.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32266

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in wp-buy 404 Image Redirection (Replace Broken Images) broken-images-redirection allows Cross Site Request Forgery.This issue affects 404 Image Redirection (Replace Broken Images): from n/a through <= 1.4.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32265

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mubarak JobWP jobwp allows Cross Site Request Forgery.This issue affects JobWP: from n/a through <= 2.3.9.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32264

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite allows Cross Site Request Forgery.This issue affects UltraAddons Elementor Lite: from n/a through <= 2.0.2.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32263

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce sequential-order-numbers-for-woocommerce allows Cross Site Request Forgery.This issue affects Sequential Order Numbers for WooCommerce: from n/a through <= 3.6.2.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32262

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Robert D Payne RDP Wiki Embed rdp-wiki-embed allows Cross Site Request Forgery.This issue affects RDP Wiki Embed: from n/a through <= 1.2.20.

    Published: 4 Apr 2025
    4.3
    Medium

    CVE-2025-32261

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Kuppuraj Advanced All in One Admin Search by WP Spotlight wp-spotlight-search allows Cross Site Request Forgery.This issue affects Advanced All in One Admin Search by WP Spotlight: from n/a through <= 1.1.1.

    Published: 4 Apr 2025