4.3

CVSS3.1

CVE-2025-9944 - Professional Contact Form <= 1.0.0 - Cross-Site Request Forgery to Test Email Sending

The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the watch_for_contact_form_submit function. This makes it possible for unauthenticated attackers to tri…

πŸ“… Published: Sept. 27, 2025, 6:47 a.m. πŸ”„ Last Modified: April 20, 2026, 7:30 p.m.

4.3

CVSS3.1

CVE-2025-9898 - cForms – Light speed fast Form Builder <= 3.0.0 - Cross-Site Request Forgery

The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the cforms_api function. This makes it possible for unauthenticated attackers to modify fo…

πŸ“… Published: Sept. 27, 2025, 6:47 a.m. πŸ”„ Last Modified: April 20, 2026, 10 p.m.

6.1

CVSS3.1

CVE-2025-9899 - Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms <= 1.0 - Cross-Site …

The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the feed_save function. This makes it possible for u…

πŸ“… Published: Sept. 27, 2025, 6:47 a.m. πŸ”„ Last Modified: April 20, 2026, 7:30 p.m.

4.3

CVSS3.1

CVE-2025-9894 - Sync Feedly <= 1.0.1 - Cross-Site Request Forgery to Sync Trigger

The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the crsf_cron_job_func function. This makes it possible for unauthenticated attackers to trigger content synchronizat…

πŸ“… Published: Sept. 27, 2025, 6:47 a.m. πŸ”„ Last Modified: April 21, 2026, 2:45 a.m.

4.3

CVSS3.1

CVE-2025-9896 - HidePost <= 2.3.8 - Cross-Site Request Forgery

The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.8. This is due to missing or incorrect nonce validation on the options.php settings page. This makes it possible for unauthenticated attackers to modify plugin settings via a forg…

πŸ“… Published: Sept. 27, 2025, 6:47 a.m. πŸ”„ Last Modified: April 22, 2026, 2:30 p.m.

5.3

CVSS4.0

CVE-2025-11051 - SourceCodester Pet Grooming Management Software cross-site request forgery

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely.

πŸ“… Published: Sept. 27, 2025, 6:32 a.m. πŸ”„ Last Modified: Oct. 3, 2025, 3:37 p.m.

7.5

CVSS3.1

CVE-2025-3193 - algoliasearch-helper: algoliasearch-helper prototype pollution

Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge() function in merge.js, which allows constructor.prototype to be written even though doing so throws an error. In the "extreme edge-case" that the resulting error is cau…

πŸ“… Published: Sept. 27, 2025, 5 a.m. πŸ”„ Last Modified: Oct. 5, 2025, 12:15 a.m.

6.9

CVSS4.0

CVE-2025-10954 -

Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of Input in the phonenumbers.Parse() function. An attacker can cause a panic by providing crafted input causing a "runtime error: slice bounds out of range".

πŸ“… Published: Sept. 27, 2025, 5 a.m. πŸ”„ Last Modified: Oct. 3, 2025, 6:30 p.m.

5.3

CVSS4.0

CVE-2025-11050 - Portabilis i-Educar periodo-lancamento improper authorization

A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been published and may be used.

πŸ“… Published: Sept. 27, 2025, 4:32 a.m. πŸ”„ Last Modified: Oct. 3, 2025, 6:28 p.m.

7.2

CVSS3.1

CVE-2025-9816 - WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unau…

πŸ“… Published: Sept. 27, 2025, 4:26 a.m. πŸ”„ Last Modified: April 20, 2026, 7:30 p.m.
Total resulsts: 349182
Page 3657 of 34,919
Β« previous page Β» next page
Filters