9.9

CVSS3.1

CVE-2025-68554 - WordPress Keenarch theme < 2.0.1 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Keenarch keenarch allows Using Malicious Files.This issue affects Keenarch: from n/a through < 2.0.1.

πŸ“… Published: March 5, 2026, 5:53 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

9.9

CVSS3.1

CVE-2025-68553 - WordPress Lendiz theme < 2.0.1 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Lendiz lendiz allows Upload a Web Shell to a Web Server.This issue affects Lendiz: from n/a through < 2.0.1.

πŸ“… Published: March 5, 2026, 5:53 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

5.8

CVSS3.1

CVE-2025-68515 - WordPress WP Booking System plugin <= 2.0.19.12 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in Roland Murg WP Booking System wp-booking-system allows Retrieve Embedded Sensitive Data.This issue affects WP Booking System: from n/a through <= 2.0.19.12.

πŸ“… Published: March 5, 2026, 5:53 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

9.8

CVSS3.1

CVE-2025-54001 - WordPress Classter theme <= 2.5 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in ThemeREX Classter classter allows Object Injection.This issue affects Classter: from n/a through <= 2.5.

πŸ“… Published: March 5, 2026, 5:53 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

8.1

CVSS3.1

CVE-2025-53335 - WordPress Berger theme <= 1.1.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Berger berger allows PHP Local File Inclusion.This issue affects Berger: from n/a through <= 1.1.1.

πŸ“… Published: March 5, 2026, 5:53 a.m. πŸ”„ Last Modified: April 22, 2026, 9:26 p.m.

7.7

CVSS3.1

CVE-2026-29053 - Ghost Vulnerable to Remote Code Execution via Malicious Themes

Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can execute arbitrary code on the server running Ghost. This issue has been patched in version 6.19.1.

πŸ“… Published: March 5, 2026, 5:51 a.m. πŸ”„ Last Modified: April 17, 2026, 1 p.m.

6.9

CVSS4.0

CVE-2026-29052 - HumHub Calendar Module: Stored XSS in Event Types

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users…

πŸ“… Published: March 5, 2026, 5:48 a.m. πŸ”„ Last Modified: April 16, 2026, 1 p.m.

9.8

CVSS3.1

CVE-2026-23767 - Unrestricted ESC/POS Commands Enable Unauthorized Printing

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

πŸ“… Published: March 5, 2026, 5:34 a.m. πŸ”„ Last Modified: April 17, 2026, 1 p.m.

6.9

CVSS4.0

CVE-2026-30777 - Multi‑Factor Authentication Bypass in EC‑Cube Administrator Login

EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who has obtained a valid administrator ID and password may be able to bypass two-factor authentication and gain unauthorized access to the administrative page.

πŸ“… Published: March 5, 2026, 5:31 a.m. πŸ”„ Last Modified: April 16, 2026, 1 p.m.

5.1

CVSS4.0

CVE-2026-27982 - django-allauth: django-allauth: Open redirect via crafted URL in SAML IdP initiated SSO

An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled (it is disabled by default), which may allow an attacker to redirect users to an arbitrary external website via a crafted URL.

πŸ“… Published: March 5, 2026, 5:31 a.m. πŸ”„ Last Modified: April 17, 2026, 1 p.m.
Total resulsts: 349182
Page 1332 of 34,919
Β« previous page Β» next page
Filters