5.3

CVSS4.0

CVE-2025-11439 - JhumanJ OpnForm integrations authorization

A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/integrations. Performing manipulation results in missing authorization. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The patch…

πŸ“… Published: Oct. 8, 2025, 6:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:18 p.m.

5.3

CVSS4.0

CVE-2025-11438 - JhumanJ OpnForm API Endpoint custom-domains authorization

A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /custom-domains of the component API Endpoint. Such manipulation leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed to the public and m…

πŸ“… Published: Oct. 8, 2025, 6:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:17 p.m.

4.8

CVSS4.0

CVE-2025-11437 - JhumanJ OpnForm Form Editor forms cross site scripting

A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the component Form Editor. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This issue is currently …

πŸ“… Published: Oct. 8, 2025, 6:02 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:18 p.m.

7.7

CVSS3.1

CVE-2025-10635 - Find Me On <= 2.0.9.1 - Subscriber+ SQL Injection

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

πŸ“… Published: Oct. 8, 2025, 6 a.m. πŸ”„ Last Modified: April 28, 2026, 10:45 a.m.

5.3

CVSS4.0

CVE-2025-11436 - JhumanJ OpnForm answer unrestricted upload

A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the file /answer. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit is now public and may be used. The patch is identified as 95c3e238…

πŸ“… Published: Oct. 8, 2025, 5:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:19 p.m.

5.3

CVSS4.0

CVE-2025-11435 - JhumanJ OpnForm submissions cross site scripting

A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may …

πŸ“… Published: Oct. 8, 2025, 5:32 a.m. πŸ”„ Last Modified: Oct. 9, 2025, 4:20 p.m.

5.3

CVSS3.1

CVE-2025-11171 - Chartify – WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that dispatches to admin-class methods based on a request parameter, wi…

πŸ“… Published: Oct. 8, 2025, 5:24 a.m. πŸ”„ Last Modified: April 21, 2026, 2:30 a.m.

6.9

CVSS4.0

CVE-2025-11434 - itsourcecode Student Transcript Processing System login.php sql injection

A weakness has been identified in itsourcecode Student Transcript Processing System 1.0. Affected is an unknown function of the file /login.php. Executing a manipulation of the argument uname can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made availabl…

πŸ“… Published: Oct. 8, 2025, 5:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

5.1

CVSS4.0

CVE-2025-11433 - itsourcecode Leave Management System Query Parameter controller.php redirect cross site scripting

A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query Parameter Handler. Performing a manipulation of the argument ID results in cross site scripting. It is …

πŸ“… Published: Oct. 8, 2025, 5:02 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

6.9

CVSS4.0

CVE-2025-11432 - itsourcecode Leave Management System reset.php sql injection

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

πŸ“… Published: Oct. 8, 2025, 4:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 6:51 a.m.
Total resulsts: 349182
Page 3511 of 34,919
Β« previous page Β» next page
Filters