4.9

CVSS3.1

CVE-2025-10045 - onOffice for WP-Websites <= 6.5.1 - Authenticated (Editor+) SQL Injection

The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and including, 6.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-10310 - Rich Snippet Site Report <= 2.0.0105 - Authenticated (Admin+) SQL Injection

The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versions up to, and including, 2.0.0105 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-10660 - WP Dashboard Chat <= 1.0.3 - Authenticated (Contributor+) SQL Injection via id

The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-10648 - Login with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensit…

The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to re…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2025-10293 - Keyy Two Factor Authentication (like Clef) <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalat…

The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity associated with a token generated. This makes it possible f…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 10:15 p.m.

6.4

CVSS3.1

CVE-2025-10139 - WP BookWidgets <= 0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcode in all versions up to, and including, 0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack…

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 10:15 p.m.

7.2

CVSS3.1

CVE-2025-10754 - DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Upload

The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Editor-level access and above, to upload …

📅 Published: Oct. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 10:15 p.m.

8.6

CVSS4.0

CVE-2025-61941 -

A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered by an administrative user who logs in to the affected product. Moreover, arbitrary OS command may be executed via some file alteration.

📅 Published: Oct. 15, 2025, 7:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-11501 - Dynamically Display Posts <= 1.1 - Unauthenticated SQL Injection

The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all versions up to, and including, 1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…

📅 Published: Oct. 15, 2025, 7:23 a.m. 🔄 Last Modified: April 21, 2026, 2:30 a.m.

6.5

CVSS3.1

CVE-2025-55039 - Apache Spark, Apache Spark: RPC encryption defaults to unauthenticated AES-CTR mode, enabling man-i…

This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 and 3.4.4 use an insecure default network encryption cipher for RPC communication between nodes. When spark.network.crypto.enabled is set to true (it is set to false by default), b…

📅 Published: Oct. 15, 2025, 7:19 a.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 349182
Page 3410 of 34,919
« previous page » next page
Filters