5.1

CVSS4.0

CVE-2025-11939 - ChurchCRM Backup Restore RestoreJob.php path traversal

A vulnerability was determined in ChurchCRM up to 5.18.0. This issue affects some unknown processing of the file src/ChurchCRM/Backup/RestoreJob.php of the component Backup Restore Handler. Executing a manipulation of the argument restoreFile can lead to path traversal. The attack may be launched r…

πŸ“… Published: Oct. 19, 2025, 8:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

6.3

CVSS4.0

CVE-2025-11938 - ChurchCRM setup.php deserialization

A vulnerability was found in ChurchCRM up to 5.18.0. This vulnerability affects unknown code of the file setup/routes/setup.php. Performing a manipulation of the argument DB_PASSWORD/ROOT_PATH/URL results in deserialization. The attack may be initiated remotely. The attack's complexity is rated as …

πŸ“… Published: Oct. 19, 2025, 7:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 8:16 a.m.

5.3

CVSS3.1

CVE-2025-62672 -

rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachable via packet data with no authentication.

πŸ“… Published: Oct. 19, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

8.8

CVSS3.1

CVE-2025-47410 - Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can …

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This …

πŸ“… Published: Oct. 18, 2025, 3:15 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.4

CVSS3.1

CVE-2025-11926 - Related Posts Lite <= 1.12 - Authenticated (Admin+) Stored Cross-Site Scripting

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

πŸ“… Published: Oct. 18, 2025, 9:25 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

8.8

CVSS3.1

CVE-2025-9890 - Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution v…

πŸ“… Published: Oct. 18, 2025, 8:25 a.m. πŸ”„ Last Modified: April 8, 2026, 5:01 p.m.

8.5

CVSS4.0

CVE-2025-5555 - Nixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflow

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been…

πŸ“… Published: Oct. 18, 2025, 8:02 a.m. πŸ”„ Last Modified: Oct. 21, 2025, 7:31 p.m.

5.3

CVSS3.1

CVE-2025-10750 - PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hook…

πŸ“… Published: Oct. 18, 2025, 7:26 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

5.3

CVSS3.1

CVE-2025-11256 - Kognetiks Chatbot <= 2.3.5 - Missing Authorization to Unauthenticated Limited File Uploads and Conv…

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations.

πŸ“… Published: Oct. 18, 2025, 7:26 a.m. πŸ”„ Last Modified: April 8, 2026, 4:40 p.m.

7.5

CVSS3.1

CVE-2025-11691 - PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions up to, and including, 33.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.
Total resulsts: 343968
Page 2852 of 34,397
Β« previous page Β» next page
Filters