6.5

CVSS3.1

CVE-2025-68040 - WordPress WP Project Manager plugin <= 3.0.1 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1.

๐Ÿ“… Published: Dec. 29, 2025, 11:25 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

5.4

CVSS3.1

CVE-2023-41656 - WordPress Better Elementor Addons plugin <= 1.3.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in wpdive Better Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Elementor Addons: from n/a through 1.3.7.

๐Ÿ“… Published: Dec. 29, 2025, 11:22 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2023-32238 - WordPress TheGem theme < 5.8.1.1 - Broken Access Control vulnerability

Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1.

๐Ÿ“… Published: Dec. 29, 2025, 11:18 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:08 p.m.

6.5

CVSS3.1

CVE-2025-68498 - WordPress JetTabs plugin <= 2.2.12 - Broken Access Control vulnerability

Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetTabs: from n/a through <= 2.2.12.

๐Ÿ“… Published: Dec. 29, 2025, 11:13 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

6.5

CVSS3.1

CVE-2025-68499 - WordPress JetTabs plugin <= 2.2.12 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12.

๐Ÿ“… Published: Dec. 29, 2025, 11:10 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

5.3

CVSS4.0

CVE-2025-15209 - code-projects Refugee Food Management System editfood.php sql injection

A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown part of the file /home/editfood.php. This manipulation of the argument a/b/c/d causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public anโ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 11:02 p.m. ๐Ÿ”„ Last Modified: Jan. 5, 2026, 10:23 a.m.

6.3

CVSS4.0

CVE-2025-15284 - arrayLimit bypass in bracket notation allows DoS via memory exhaustion

Improper Input Validation vulnerability in qs (parse modules) allows HTTP DoS.This issue affects qs: < 6.14.1. Summary The arrayLimitย option in qs did not enforce limits for bracket notation (a[]=1&a[]=2), only for indexed notation (a[0]=1). This is a consistency bug; arrayLimitย should apply uniโ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 10:56 p.m. ๐Ÿ”„ Last Modified: Feb. 26, 2026, 7:57 p.m.

6.9

CVSS4.0

CVE-2025-15208 - code-projects Refugee Food Management System editrefugee.php sql injection

A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injection. The attack can be launched remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 10:32 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 8:51 p.m.

6.9

CVSS4.0

CVE-2025-15207 - Campcodes Supplier Management System view_products.php sql injection

A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the puโ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:12 a.m.

6.9

CVSS4.0

CVE-2025-15206 - Campcodes Supplier Management System add_area.php sql injection

A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be useโ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 9:32 p.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 7:17 a.m.
Total resulsts: 349182
Page 2380 of 34,919
ยซ previous page ยป next page
Filters