8.8

CVSS3.1

CVE-2025-47410 - Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can …

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricked a user into giving up their Geode session credentials to submit malicious commands on the target system on behalf of the authenticated user. This …

πŸ“… Published: Oct. 18, 2025, 3:15 p.m. πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.4

CVSS3.1

CVE-2025-11926 - Related Posts Lite <= 1.12 - Authenticated (Admin+) Stored Cross-Site Scripting

The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

πŸ“… Published: Oct. 18, 2025, 9:25 a.m. πŸ”„ Last Modified: April 22, 2026, 5 p.m.

8.8

CVSS3.1

CVE-2025-9890 - Theme Editor <= 3.0 - Cross-Site Request Forgery to Remote Code Execution

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing or incorrect nonce validation on the 'theme_editor_theme' page. This makes it possible for unauthenticated attackers to achieve remote code execution v…

πŸ“… Published: Oct. 18, 2025, 8:25 a.m. πŸ”„ Last Modified: April 21, 2026, 7 p.m.

8.5

CVSS4.0

CVE-2025-5555 - Nixdorf Wincor PORT IO Driver IOCTL wnport.sys sub_11100 stack-based overflow

A vulnerability has been found in Nixdorf Wincor PORT IO Driver up to 1.0.0.1. This affects the function sub_11100 in the library wnport.sys of the component IOCTL Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been…

πŸ“… Published: Oct. 18, 2025, 8:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-10750 - PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hook…

πŸ“… Published: Oct. 18, 2025, 7:26 a.m. πŸ”„ Last Modified: April 21, 2026, 7 p.m.

5.3

CVSS3.1

CVE-2025-11256 - Kognetiks Chatbot <= 2.3.5 - Missing Authorization to Unauthenticated Limited File Uploads and Conv…

The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.3.5. This makes it possible for unauthenticated attackers to upload limited safe files and erase conversations.

πŸ“… Published: Oct. 18, 2025, 7:26 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-11691 - PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the PPOM_Meta::get_fields_by_id() function in all versions up to, and including, 33.0.15 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 a.m.

6.5

CVSS3.1

CVE-2025-11372 - LearnPress – WordPress LMS Plugin <= 4.2.9.3 - Missing Authorization to Unauthenticated Database Ta…

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, and including, 4.2.9.2. This is due to missing capability checks on the Admin Tools REST endpoints which are registered with permission_callback set to __return_true. This makes i…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 21, 2026, 2:15 a.m.

9.8

CVSS3.1

CVE-2025-11391 - PPOM – Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated Arbitrary File U…

The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. This makes it possible for unauthenticated attackers to upload…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 21, 2026, 2:15 a.m.

6.4

CVSS3.1

CVE-2025-11270 - Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 5.7.1 - Authenticated …

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible…

πŸ“… Published: Oct. 18, 2025, 6:42 a.m. πŸ”„ Last Modified: April 21, 2026, 2:15 a.m.
Total resulsts: 349182
Page 3372 of 34,919
Β« previous page Β» next page
Filters