8.8

CVSS3.1

CVE-2025-7812 - Video Share VOD – Turnkey Video Site Builder Script <= 2.7.6 - Cross-Site Request Forgery to Comman…

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.6. This is due to missing or incorrect nonce validation on the adminExport() function. This makes it possible for unauthenticated attack…

πŸ“… Published: Aug. 28, 2025, 1:46 a.m. πŸ”„ Last Modified: Aug. 28, 2025, 1:46 a.m.

6.1

CVSS3.1

CVE-2025-8897 - Beaver Builder Plugin (Lite Version) <= 2.9.2.1 - Reflected Cross-Site Scripting

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜'fl_builder' parameter in all versions up to, and including, 2.9.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac…

πŸ“… Published: Aug. 28, 2025, 1:46 a.m. πŸ”„ Last Modified: Aug. 28, 2025, 1:46 a.m.

6.4

CVSS3.1

CVE-2025-9344 - UsersWP <= 1.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uwp_profile' and 'uwp_profile_header' shortcodes in all versions up to, and including, 1.2.42 due to insufficient…

πŸ“… Published: Aug. 28, 2025, 1:46 a.m. πŸ”„ Last Modified: Aug. 28, 2025, 1:46 a.m.

5.4

CVSS3.1

CVE-2025-9352 - Pronamic Google Maps <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acc…

πŸ“… Published: Aug. 28, 2025, 1:46 a.m. πŸ”„ Last Modified: Aug. 28, 2025, 1:46 a.m.

6.1

CVSS3.1

CVE-2025-56236 -

FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser c…

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Aug. 29, 2025, 4:24 p.m.

5.3

CVSS3.1

CVE-2025-57217 -

Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the Password parameter in the function R7WebsSecurityHandler.

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Aug. 29, 2025, 4:24 p.m.

5.3

CVSS3.1

CVE-2025-57220 -

An input validation flaw in the 'ate' service of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 to escalate privileges to root via a crafted UDP packet.

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Aug. 29, 2025, 4:24 p.m.

5.3

CVSS3.1

CVE-2025-52054 -

An issue was discovered in Tenda AC8 v4.0 AC1200 Dual-band Gigabit Wireless Router AC8v4.0 Firmware 16.03.33.05. The root password of the device is calculated with a static string and the last two octets of the MAC address of the device. This allows an unauthenticated attacker to authenticate with …

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Aug. 29, 2025, 4:24 p.m.

5.3

CVSS3.1

CVE-2025-57219 -

Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 allows attackers to escalate privileges or access sensitive components via a crafted request.

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Aug. 29, 2025, 4:24 p.m.

6.5

CVSS3.1

CVE-2025-51968 -

A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions.

πŸ“… Published: Aug. 28, 2025, midnight πŸ”„ Last Modified: Aug. 29, 2025, 4:24 p.m.
Total resulsts: 307499
Page 33 of 30,750
Β« previous page Β» next page
Filters