5.3

CVSS3.1

CVE-2025-13006 - SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.5 via several unprotected /wp-json/surveyfunnel/v2/ REST API endpoints. This makes it possible for unauthenticated attackers to extract sensi…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

9.8

CVSS3.1

CVE-2025-13313 - CRM Memberships <= 2.6 - Missing Authorization to Privilege Escalation via Unauthenticated Password…

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJAX action. This makes it possible for unauthenticated attacker…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

4.3

CVSS3.1

CVE-2025-13362 - Norby AI <= 1.0.3 - Cross-Site Request Forgery to Settings Update

The Norby AI plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's settings and inject ma…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 21, 2026, 6 p.m.

5.3

CVSS3.1

CVE-2025-13494 - SSP Debug <= 1.0.0 - Unauthenticated Sensitive Information Exposure

The SSP Debug plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0. This is due to the plugin storing PHP error logs in a predictable, web-accessible location (wp-content/uploads/ssp-debug/ssp-debug.log) without any access controls. This m…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 22, 2026, 12:30 a.m.

6.4

CVSS3.1

CVE-2025-12417 - SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Sit…

The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'surveyfunnel_lite_survey' shortcode in all versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping on user supplied attributes. This make…

📅 Published: Dec. 5, 2025, 4:29 a.m. 🔄 Last Modified: April 22, 2026, 4:30 p.m.

8.8

CVSS3.1

CVE-2025-13066 - Demo Importer Plus <= 2.0.6 - Authenticated (Author+) Arbitrary File Upload via WXR Upload Bypass

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypass sanitization while being accepted as a valid WXR file. This…

📅 Published: Dec. 5, 2025, 3:28 a.m. 🔄 Last Modified: April 21, 2026, 6 p.m.

5.1

CVSS4.0

CVE-2025-27389 - Application Installation Source Verification Flaw May Lead to Risk Detection Bypass

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without proper warning.

📅 Published: Dec. 5, 2025, 3:19 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-12804 - Booking Calendar <= 10.14.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via bookingc…

The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenti…

📅 Published: Dec. 5, 2025, 1:55 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

4.3

CVSS3.1

CVE-2025-11759 - Backup, Restore and Migrate your sites with XCloner <= 4.8.2 - Cross-Site Request Forgery in Xclone…

The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.2. This is due to missing or incorrect nonce validation on the Xcloner_Remote_Storage:save() function. This makes it possible for unauth…

📅 Published: Dec. 5, 2025, 1:55 a.m. 🔄 Last Modified: April 21, 2026, 1:15 a.m.

4.3

CVSS3.1

CVE-2025-62223 - Microsoft Edge (Chromium-based) for Mac Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

📅 Published: Dec. 5, 2025, 12:21 a.m. 🔄 Last Modified: April 20, 2026, 4:15 p.m.
Total resulsts: 349182
Page 2813 of 34,919
« previous page » next page
Filters