5.3

CVSS4.0

CVE-2025-2323 - 274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral worโ€ฆ

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been declared as problematic. This vulnerability affects the function updateQuestionCou of the file /api/mjkj-chat/chat/mng/update/questionCou of the component Number of Question Handler. The manipulation leads to enfoโ€ฆ

๐Ÿ“… Published: March 15, 2025, 5 p.m. ๐Ÿ”„ Last Modified: March 17, 2025, 4:53 p.m.

6.9

CVSS4.0

CVE-2025-2322 - 274056675 springboot-openai-chatgpt OpenController.java hard-coded credentials

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the file /chatgpt-boot/src/main/java/org/springblade/modules/mjkj/controller/OpenController.java. The manipulation leads to hard-coded credentials. It is posโ€ฆ

๐Ÿ“… Published: March 15, 2025, 1:31 p.m. ๐Ÿ”„ Last Modified: March 18, 2025, 4:18 p.m.

5.3

CVSS4.0

CVE-2025-2321 - 274056675 springboot-openai-chatgpt addData logic error

A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by this issue is some unknown functionality of the file /api/mjkj-chat/cgform-api/addData/. The manipulation of the argument chatUserID leads to business logic errors. The attack may be lauโ€ฆ

๐Ÿ“… Published: March 15, 2025, noon ๐Ÿ”„ Last Modified: March 18, 2025, 4:19 p.m.

4.3

CVSS3.1

CVE-2025-1530 - Tripetto <= 8.0.9 - Cross-Site Request Forgery to Arbitrary Results Deletion

The Tripetto plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.0.9. This is due to missing nonce validation. This makes it possible for unauthenticated attackers to delete arbitrary results via a forged request granted they can trick a site admโ€ฆ

๐Ÿ“… Published: March 15, 2025, 11:13 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:27 p.m.

6.5

CVSS3.1

CVE-2025-2025 - Give <= 3.22.0 - Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via โ€ฆ

The GiveWP โ€“ Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the give_reports_earnings() function in all versions up to, and including, 3.22.0. This makes it possible for unauthenticated attackers to disโ€ฆ

๐Ÿ“… Published: March 15, 2025, 11:13 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:27 p.m.

4.9

CVSS3.1

CVE-2019-25222 - Thumbnail carousel slider <= 1.0.4 - Authenticated (Admin+) SQL Injection

The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for โ€ฆ

๐Ÿ“… Published: March 15, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 9:27 p.m.

7.2

CVSS3.1

CVE-2025-2325 - WP Test Email <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting

The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages thโ€ฆ

๐Ÿ“… Published: March 15, 2025, 6:40 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 4:52 p.m.

7.2

CVSS3.1

CVE-2024-13497 - WordPress form builder plugin for contact forms, surveys and quizzes โ€“ Tripetto <= 8.0.9 - Unauthenโ€ฆ

The WordPress form builder plugin for contact forms, surveys and quizzes โ€“ Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attachment uploads in all versions up to, and including, 8.0.9 due to insufficient input sanitization and output escaping. This makes it possibleโ€ฆ

๐Ÿ“… Published: March 15, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 4:53 p.m.

9.8

CVSS3.1

CVE-2025-1771 - Traveler <= 3.1.8 - Unauthenticated Local File Inclusion via hotel_alone_load_more_post

The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing theโ€ฆ

๐Ÿ“… Published: March 15, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 4:54 p.m.

6.1

CVSS3.1

CVE-2025-1773 - Traveler <= 3.1.8 - Reflected Cross-Site Scripting

The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in paโ€ฆ

๐Ÿ“… Published: March 15, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: March 17, 2025, 4:55 p.m.
Total resulsts: 285663
Page 27 of 28,567
ยซ previous page ยป next page
Filters