6.9

CVSS4.0

CVE-2025-15530 - Open5GS s11-handler.c assertion

A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c. Executing a manipulation can lead to reachable assertion. The attack can be executed remotely. The exploit has been puโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 11:02 a.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 9:16 a.m.

6.4

CVSS3.1

CVE-2025-8615 - CubeWP <= 1.1.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taโ€ฆ

The CubeWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cubewp_shortcode_taxonomy shortcode in all versions up to, and including, 1.1.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 8:24 a.m. ๐Ÿ”„ Last Modified: April 20, 2026, 9:15 p.m.

5.3

CVSS3.1

CVE-2025-14078 - PAYGENT for WooCommerce <= 2.4.6 - Missing Authorization to Unauthenticated Payment Callback Manipuโ€ฆ

The PAYGENT for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.6. This is due to missing authorization checks on the paygent_check_webhook function combined with the paygent_permission_callback function unconditionally returning truโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 8:24 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 4:30 p.m.

4.4

CVSS3.1

CVE-2026-0725 - Integrate Dynamics 365 CRM <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting viโ€ฆ

The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,โ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 8:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 10 p.m.

9.8

CVSS3.1

CVE-2025-10484 - Registration & Login with Mobile Phone Number for WooCommerce <= 1.3.1 - Authentication Bypass

The Registration & Login with Mobile Phone Number for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.1. This is due to the plugin not properly verifying a users identity prior to authenticating them via the fma_lwp_set_session_php_fโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 8:24 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 2 p.m.

7.5

CVSS3.1

CVE-2025-14478 - Demo Importer Plus <= 2.0.9 - Authenticated (Author+) Blind XML External Entity Injection via SVG Fโ€ฆ

The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vuโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 7:27 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 12:30 a.m.

5.3

CVSS3.1

CVE-2025-12129 - CubeWP โ€“ All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information Exposure

The CubeWP โ€“ All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.27 via the /cubewp-posts/v1/query-new and /cubewp-posts/v1/query REST API endpoints due to insufficient restrictions on which posts can be included.โ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 7:27 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, 8:15 p.m.

5.3

CVSS3.1

CVE-2026-0808 - Spin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter

The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or randomization. This makes it possible for unauthenticated attackโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 6:42 a.m. ๐Ÿ”„ Last Modified: April 16, 2026, 6:15 p.m.

4.4

CVSS3.1

CVE-2026-0691 - CM E-Mail Blacklist <= 1.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'blacโ€ฆ

The CM E-Mail Blacklist โ€“ Simple email filtering for safer registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'black_email' parameter in all versions up to, and including, 1.6.2. This is due to insufficient input sanitization and output escaping. This makes it poโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 6:42 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 10 p.m.

4.9

CVSS3.1

CVE-2025-12984 - Advanced Ads โ€“ Ad Manager & AdSense <= 2.0.15 - Authenticated (Admin+) SQL Injection

The Advanced Ads โ€“ย Ad Manager & AdSense plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 2.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes itโ€ฆ

๐Ÿ“… Published: Jan. 17, 2026, 6:42 a.m. ๐Ÿ”„ Last Modified: April 22, 2026, midnight
Total resulsts: 349182
Page 2087 of 34,919
ยซ previous page ยป next page
Filters