4.3

CVSS3.1

CVE-2025-68502 - WordPress JetPopup plugin <= 2.0.20.1 - Insecure Direct Object References (IDOR) vulnerability

Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through <= 2.0.20.1.

๐Ÿ“… Published: Dec. 29, 2025, 9:16 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

6.5

CVSS3.1

CVE-2025-68503 - WordPress JetBlog plugin <= 2.4.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.

๐Ÿ“… Published: Dec. 29, 2025, 9:15 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

6.5

CVSS3.1

CVE-2025-68504 - WordPress JetSearch plugin <= 3.5.16 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16.

๐Ÿ“… Published: Dec. 29, 2025, 9:14 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:35 p.m.

9.9

CVSS3.1

CVE-2025-68562 - WordPress MapSVG plugin <= 8.7.3 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

๐Ÿ“… Published: Dec. 29, 2025, 9:13 p.m. ๐Ÿ”„ Last Modified: April 28, 2026, 4:14 p.m.

6.5

CVSS3.1

CVE-2025-68607 - WordPress Custom Field Template plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Stored XSS.This issue affects Custom Field Template: from n/a through <= 2.7.7.

๐Ÿ“… Published: Dec. 29, 2025, 9:10 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

9.8

CVSS3.1

CVE-2025-68860 - WordPress Mobile builder plugin <= 1.4.2 - Broken Authentication vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in Mobile Builder Mobile builder mobile-builder allows Authentication Abuse.This issue affects Mobile builder: from n/a through <= 1.4.2.

๐Ÿ“… Published: Dec. 29, 2025, 9:08 p.m. ๐Ÿ”„ Last Modified: April 23, 2026, 3:36 p.m.

5.3

CVSS4.0

CVE-2025-15205 - code-projects Student File Management System download.php sql injection

A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download.php. The manipulation of the argument istore_id leads to sql injection. The attack can be initiated remotely. The exploit is publicly โ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 9:02 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 3 p.m.

6.3

CVSS3.1

CVE-2025-69205 - In ยตURU, a Specially Crafted Federation Name Allows Dialplan Injection

Micro Registration Utility (ยตURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a special federation name and characters treated special by asterisk can be injected into the `Dial( โ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 8:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-15204 - SohuTV CacheCloud QuartzManageController.java doQuartzList cross site scripting

A vulnerability was determined in SohuTV CacheCloud up to 3.2.0. Affected is the function doQuartzList of the file src/main/java/com/sohu/cache/web/controller/QuartzManageController.java. Executing manipulation can lead to cross site scripting. It is possible to launch the attack remotely. The explโ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 9:35 p.m.

4.8

CVSS4.0

CVE-2025-15203 - SohuTV CacheCloud ResourceController.java index cross site scripting

A vulnerability was found in SohuTV CacheCloud up to 3.2.0. This impacts the function index of the file src/main/java/com/sohu/cache/web/controller/ResourceController.java. Performing manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been โ€ฆ

๐Ÿ“… Published: Dec. 29, 2025, 8:02 p.m. ๐Ÿ”„ Last Modified: Jan. 6, 2026, 9:36 p.m.
Total resulsts: 349182
Page 2381 of 34,919
ยซ previous page ยป next page
Filters