5.1

CVSS4.0

CVE-2025-12914 - aaPanel BaoTa Backend database sql injection

A vulnerability has been found in aaPanel BaoTa up to 11.1.0. This vulnerability affects unknown code of the file /database?action=GetDatabaseAccess of the component Backend. The manipulation of the argument Name leads to sql injection. The attack can be initiated remotely. The exploit has been dis…

📅 Published: Nov. 8, 2025, 9:32 p.m. 🔄 Last Modified: Nov. 8, 2025, 9:32 p.m.

5.1

CVSS4.0

CVE-2025-12913 - code-projects Responsive Hotel Site roomdel.php sql injection

A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomdel.php. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

📅 Published: Nov. 8, 2025, 8:02 p.m. 🔄 Last Modified: Nov. 8, 2025, 8:02 p.m.

7.2

CVSS3.1

CVE-2025-12399 - Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with…

📅 Published: Nov. 8, 2025, 9:28 a.m. 🔄 Last Modified: Nov. 8, 2025, 10:15 a.m.

7.2

CVSS3.1

CVE-2025-11967 - Mail Mint <= 1.18.10 - Authenticated (Admin+) Arbitrary File Upload

The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_import function in all versions up to, and including, 1.18.10. This makes it possible for authenticated attackers, with Administrator-level access and abov…

📅 Published: Nov. 8, 2025, 9:28 a.m. 🔄 Last Modified: Nov. 8, 2025, 10:15 a.m.

4.3

CVSS3.1

CVE-2025-11448 - Gallery Plugin for WordPress – Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authentica…

The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/envira-convert/v1/bulk-convert' REST API endpoint in all versions up to, and including, 1.11.0. This makes it possible for authe…

📅 Published: Nov. 8, 2025, 9:28 a.m. 🔄 Last Modified: Nov. 8, 2025, 10:15 a.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@arslan

CVE stats coming here

avatar

Mücahit İç

@mucahic

CVE stats coming here

avatar

Muhammed Emir ARSLAN

@MrM3ARS

CVE stats coming here