5.4

CVSS3.1

CVE-2025-30191 -

Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensitive information to a third party which would enable further threats. Attribute values containing HTML fragments are now denied by the sanitization procedure.…

πŸ“… Published: Oct. 31, 2025, 8:54 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-30188 -

Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No publicly available ex…

πŸ“… Published: Oct. 31, 2025, 8:54 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

7.5

CVSS3.1

CVE-2025-62232 - Apache APISIX: basic-auth logs plaintext credentials at info level

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit:Β  https://githu…

πŸ“… Published: Oct. 31, 2025, 8:48 a.m. πŸ”„ Last Modified: Nov. 5, 2025, 2:44 p.m.

4.3

CVSS3.1

CVE-2025-8383 - Depicter <= 4.0.4 - Cross-Site Request Forgery

The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4. This is due to missing or incorrect nonce validation on the depicter-document-rules-store function. This makes it possible for unauthenticated attackers to modify document rules …

πŸ“… Published: Oct. 31, 2025, 8:25 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

5.3

CVSS3.1

CVE-2025-12094 - OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 - Unauthen…

The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up to, and including, 1.2.53. This is due to the plugin trusting client-controlled forwarded headers (such as CF-Connecting-IP, X-Forwarded-For…

πŸ“… Published: Oct. 31, 2025, 8:25 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

4.3

CVSS3.1

CVE-2025-12175 - The Events Calendar <= 6.15.9 - Missing Authorization to Authenticated (Subscriber+) Draft Event Ti…

The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'tec_qr_code_modal' AJAX endpoint in all versions up to, and including, 6.15.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to v…

πŸ“… Published: Oct. 31, 2025, 8:25 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

9.8

CVSS3.1

CVE-2025-6520 - SQLi in Abis Technology's BAPSIS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection.This issue affects BAPSIS: before 202510271606.

πŸ“… Published: Oct. 31, 2025, 7:44 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

6.8

CVSS3.1

CVE-2025-8385 - Zombify <= 1.7.5 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read

The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is due to insufficient input validation in the zf_get_file_by_url function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read arbitrar…

πŸ“… Published: Oct. 31, 2025, 7:26 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.6

CVSS3.1

CVE-2025-10897 - WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.

πŸ“… Published: Oct. 31, 2025, 7:26 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.

8.8

CVSS3.1

CVE-2025-7846 - WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_…

The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for authenticated attackers, with Subscriber-level access and above…

πŸ“… Published: Oct. 31, 2025, 6:42 a.m. πŸ”„ Last Modified: Nov. 4, 2025, 3:41 p.m.
Total resulsts: 318124
Page 164 of 31,813
Β« previous page Β» next page
Filters