7.1

CVSS3.1

CVE-2024-14015 - Studiocart <= 2.9.0 - Reflected XSS

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: Nov. 24, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-13585 - itsourcecode COVID Tracking System login.php sql injection

A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

๐Ÿ“… Published: Nov. 24, 2025, 5:32 a.m. ๐Ÿ”„ Last Modified: Dec. 7, 2025, 4:15 p.m.

5.1

CVSS4.0

CVE-2025-13584 - Eigenfocus Description cross site scripting

A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the component Description Handler. The manipulation of the argument entry.description/time_entry.description leads to cross site scripting. The attack is possible to be carried out remotโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, 5:02 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-7402 - Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injectioโ€ฆ

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜site_idโ€™ parameter in all versions up to, and including, 4.95 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on thโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, 4:36 a.m. ๐Ÿ”„ Last Modified: April 21, 2026, 1:30 a.m.

6.9

CVSS4.0

CVE-2025-13583 - code-projects Question Paper Generator POST Parameter signupscript.php sql injection

A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulation of the argument Fname can lead to sql injection. The attack can be executed remotely. The exploit โ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, 4:32 a.m. ๐Ÿ”„ Last Modified: Dec. 2, 2025, 3:11 a.m.

6.9

CVSS4.0

CVE-2025-13582 - code-projects Jonnys Liquor GET Parameter detail.php sql injection

A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functionality of the file /detail.php of the component GET Parameter Handler. Performing manipulation of the argument Product results in sql injection. Remote exploitation of the attack isโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, 4:02 a.m. ๐Ÿ”„ Last Modified: Dec. 2, 2025, 3:12 a.m.

5.3

CVSS4.0

CVE-2025-13581 - itsourcecode Student Information System schedule_edit1.php sql injection

A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /schedule_edit1.php. Such manipulation of the argument schedule_id leads to sql injection. The attack may be launched remotely. The exploit is publicโ€ฆ

๐Ÿ“… Published: Nov. 24, 2025, 3:32 a.m. ๐Ÿ”„ Last Modified: Dec. 1, 2025, 5:42 p.m.

5.1

CVSS4.0

CVE-2025-13589 - Otsuka Information Technology๏ฝœFMS - Reflected Cross-site Scripting

FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

๐Ÿ“… Published: Nov. 24, 2025, 3:09 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-13580 - code-projects Library System mail.php sql injection

A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

๐Ÿ“… Published: Nov. 24, 2025, 3:02 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:38 a.m.

5.3

CVSS4.0

CVE-2025-13579 - code-projects Library System return.php sql injection

A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

๐Ÿ“… Published: Nov. 24, 2025, 2:32 a.m. ๐Ÿ”„ Last Modified: Feb. 24, 2026, 6:37 a.m.
Total resulsts: 349182
Page 2920 of 34,919
ยซ previous page ยป next page
Filters