6.4
CVE-2025-9075 - ZoloBlocks β Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patteβ¦
The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google Mβ¦
4
CVE-2025-10735 - Block For Mailchimp β Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Sideβ¦
The Block For Mailchimp β Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.12 via the mcbSubmit_Form_Data(). This makes it possible for unauthenticated attackers to make web requests to arbitrary locatiβ¦
5.3
CVE-2025-10744 - File Manager, Code editor, backup by Managefy <= 1.6.1 - Unauthenticated Information Exposure
The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view information like full paths and fulβ¦
0.0
CVE-2025-59684 -
DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.
0.0
CVE-2025-56515 -
File upload vulnerability in Fiora chat application 1.0.0 through user avatar upload functionality. The application fails to validate SVG file content, allowing malicious SVG files with embedded foreignObject elements containing iframe tags and JavaScript event handlers (onmouseover) to be uploadedβ¦
0.0
CVE-2025-57393 -
A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
7.1
CVE-2025-59681 -
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as theβ¦
0.0
CVE-2025-57444 -
An authenticated cross-site scripting (XSS) vulnerability in the Administrative interface of Radware AlteonOS Web UI Management v33.0.4.50 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Description parameter.
0.0
CVE-2024-57494 -
Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.
0.0
CVE-2025-46205 -
A heap-use-after free in the PdfTokenizer::ReadDictionary function of podofo v0.10.0 to v0.10.5 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PDF file.