0.0

CVE-2025-49345 - WordPress WP-EasyArchives plugin <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue affects WP-EasyArchives: from n/a through <= 3.1.2.

πŸ“… Published: Dec. 31, 2025, 5:23 a.m. πŸ”„ Last Modified: April 1, 2026, 5:25 p.m.

5.3

CVSS4.0

CVE-2025-15375 - EyouCMS arcpagelist Ajax.php unserialize deserialization

A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be launched remotely. The …

πŸ“… Published: Dec. 31, 2025, 5:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

0.0

CVE-2025-49346 - WordPress Simple Archive Generator plugin <= 5.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Stored XSS.This issue affects Simple Archive Generator: from n/a through <= 5.2.

πŸ“… Published: Dec. 31, 2025, 4:37 a.m. πŸ”„ Last Modified: April 1, 2026, 5:25 p.m.

0.0

CVE-2025-59137 - WordPress Behance Portfolio Manager plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerabili…

Cross-Site Request Forgery (CSRF) vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5.

πŸ“… Published: Dec. 31, 2025, 4:33 a.m. πŸ”„ Last Modified: April 1, 2026, 5:27 p.m.

5.1

CVSS4.0

CVE-2025-15374 - EyouCMS Ask Module Ask.php cross site scripting

A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the component Ask Module. Performing a manipulation of the argument content results in cross site scripting. The attack can be initiated remotely. The explo…

πŸ“… Published: Dec. 31, 2025, 4:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.

5.3

CVSS4.0

CVE-2025-15373 - EyouCMS function.php saveRemote server-side request forgery

A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.…

πŸ“… Published: Dec. 31, 2025, 4:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:19 a.m.

5.3

CVSS4.0

CVE-2025-15223 - Philipinho Simple-PHP-Blog login.php cross site scripting

A vulnerability was found in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. Impacted is an unknown function of the file /login.php. Performing manipulation of the argument Username results in cross site scripting. The attack is possible to be carried out remotely. The ex…

πŸ“… Published: Dec. 31, 2025, 2:32 a.m. πŸ”„ Last Modified: Jan. 29, 2026, 4:50 p.m.

4.8

CVSS4.0

CVE-2025-15372 - youlaitech vue3-element-admin Notice index.vue cross site scripting

A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing of the file src/views/system/notice/index.vue of the component Notice Handler. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The e…

πŸ“… Published: Dec. 31, 2025, 2:02 a.m. πŸ”„ Last Modified: Jan. 15, 2026, 1:41 a.m.

5.5

CVSS4.0

CVE-2025-68131 - CBORDecoder reuse can leak shareable values across decode calls

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Starting in version 3.0.0 and prior to version 5.8.0, whhen a CBORDecoder instance is reused across multiple decode operations, values marked with the shareable tag (28) persist in memory …

πŸ“… Published: Dec. 31, 2025, 1:15 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

8.5

CVSS4.0

CVE-2025-15371 - Tenda i24 Shadow File hard-coded credentials

A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The…

πŸ“… Published: Dec. 31, 2025, 1:02 a.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.
Total resulsts: 343921
Page 1811 of 34,393
Β« previous page Β» next page
Filters