4.4

CVSS3.1

CVE-2025-12451 - Easy SVG Support <= 4.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, t…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 21, 2026, 4 p.m.

7.5

CVSS3.1

CVE-2025-11754 - Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePriva…

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin sett…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, 12:15 p.m.

4.3

CVSS3.1

CVE-2025-12172 - Mailchimp List Subscribe Form <= 2.0.0 - Cross-Site Request Forgery to Mailchimp List Change

The Mailchimp List Subscribe Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on the mailchimp_sf_change_list_if_necessary() function. This makes it possible for unauthenticated at…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, noon

6.1

CVSS3.1

CVE-2025-11706 - Aruba HiSpeed Cache <= 3.0.2 - Reflected Cross-Site Scripting

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the dbstatus parameter in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, 12:15 p.m.

6.4

CVSS3.1

CVE-2025-12448 - Smartsupp – live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) St…

The Smartsupp – live chat, AI shopping assistant and chatbots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'code' parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, noon

6.5

CVSS3.1

CVE-2025-11725 - Aruba HiSpeed Cache <= 3.0.2 - Missing Authorization to Unauthenticated Plugin's Settings Modificat…

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the multiple functions in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to modify plugin's configuration settings, e…

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, 8 p.m.

4.3

CVSS3.1

CVE-2025-12027 - Mesmerize Companion <= 1.6.158 - Missing Authorization Authenticated (Subscriber+) Settings Update

The Mesmerize Companion plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the "openPageInCustomizer" and "openPageInDefaultEditor" functions in all versions up to, and including, 1.6.158. This makes it possible for authenticated …

📅 Published: Feb. 19, 2026, 3:25 a.m. 🔄 Last Modified: April 22, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2026-25474 - OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth …

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployments where the webhook endpoint is reachable by an…

📅 Published: Feb. 19, 2026, 2:38 a.m. 🔄 Last Modified: April 18, 2026, noon

5.3

CVSS4.0

CVE-2026-25229 - Gogs Authorization Bypass Allows Cross-Repository Label Modification

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabel function in the Web UI (internal/route/repo/iss…

📅 Published: Feb. 19, 2026, 2:33 a.m. 🔄 Last Modified: April 18, 2026, noon

5.3

CVSS4.0

CVE-2026-2693 - CoCoTeaNet CyreneAdmin System Info Endpoint getCount improper authorization

A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System Info Endpoint. Executing a manipulation can lead to improper authorization. The attack can be launched remotely. The explo…

📅 Published: Feb. 19, 2026, 2:32 a.m. 🔄 Last Modified: April 17, 2026, 6:30 p.m.
Total resulsts: 349182
Page 1578 of 34,919
« previous page » next page
Filters