7.1

CVSS3.1

CVE-2025-12551 - WordPress ListingHub plugin 1.2.6 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins ListingHub listinghub allows Reflected XSS.This issue affects ListingHub: from n/a through 1.2.6.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.1

CVSS3.1

CVE-2025-12550 - WordPress OchaHouse theme <= 2.2.8 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes OchaHouse ochahouse allows PHP Local File Inclusion.This issue affects OchaHouse: from n/a through <= 2.2.8.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

8.1

CVSS3.1

CVE-2025-12549 - WordPress Rozy - Flower Shop theme <= 1.2.25 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Rozy - Flower Shop rozy allows PHP Local File Inclusion.This issue affects Rozy - Flower Shop: from n/a through <= 1.2.25.

πŸ“… Published: Jan. 8, 2026, 9:17 a.m. πŸ”„ Last Modified: April 24, 2026, 6:28 p.m.

5.1

CVSS4.0

CVE-2026-0701 - code-projects Intern Membership Management System add_admin.php sql injection

A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /intern/admin/add_admin.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out rem…

πŸ“… Published: Jan. 8, 2026, 8:02 a.m. πŸ”„ Last Modified: April 18, 2026, 8 a.m.

6.5

CVSS3.1

CVE-2025-13679 - Tutor LMS <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exp…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_order_by_id() function in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber…

πŸ“… Published: Jan. 8, 2026, 7:04 a.m. πŸ”„ Last Modified: April 22, 2026, 4 p.m.

6.9

CVSS4.0

CVE-2026-0700 - code-projects Intern Membership Management System check_admin.php sql injection

A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been …

πŸ“… Published: Jan. 8, 2026, 7:02 a.m. πŸ”„ Last Modified: April 18, 2026, 5 p.m.

0.0

CVE-2026-22635 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22634 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22636 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.

0.0

CVE-2026-22631 -

Not used

πŸ“… Published: Jan. 8, 2026, 6:49 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 3:55 a.m.
Total resulsts: 346727
Page 1989 of 34,673
Β« previous page Β» next page
Filters