7.6
CVE-2025-58789 - WordPress WP Full Stripe Free Plugin <= 8.3.0 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full Stripe Free allows SQL Injection. This issue affects WP Full Stripe Free: from n/a through 8.3.0.
7.6
CVE-2025-58788 - WordPress License Manager for WooCommerce Plugin <= 3.0.12 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce allows Blind SQL Injection. This issue affects License Manager for WooCommerce: from n/a through 3.0.12.
6.5
CVE-2025-58787 - WordPress Themify Popup Plugin <= 1.4.4 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Popup allows Stored XSS. This issue affects Themify Popup: from n/a through 1.4.4.
6.5
CVE-2025-58786 - WordPress Ibtana β Ecommerce Product Addons Plugin <= 0.4.7.4 - Cross Site Scripting (XSS) Vulnerabβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana β Ecommerce Product Addons allows DOM-Based XSS. This issue affects Ibtana β Ecommerce Product Addons: from n/a through 0.4.7.4.
5.4
CVE-2025-58785 - WordPress Ray Enterprise Translation Plugin <= 1.7.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in jbhovik Ray Enterprise Translation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ray Enterprise Translation: from n/a through 1.7.1.
6.5
CVE-2025-58784 - WordPress ARI Fancy Lightbox Plugin <= 1.4.0 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy Lightbox allows Stored XSS. This issue affects ARI Fancy Lightbox: from n/a through 1.4.0.
4.3
CVE-2025-58783 - WordPress Gutentor Plugin <= 3.5.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in gutentor Gutentor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutentor: from n/a through 3.5.1.
5.4
CVE-2025-8695 - Reflected XSS in Netcad Software's NetGIS Server
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetGIS Server allows Reflected XSS.This issue affects NetGIS Server: from 5.2.4 through 22.08.2025.
3.2
CVE-2024-21977 -
Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests.
0.0
CVE-2025-58911 -
Not used