5.1

CVSS4.0

CVE-2025-40707 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:17 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 1:33 p.m.

5.1

CVSS4.0

CVE-2025-40706 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:17 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 4:55 p.m.

5.1

CVSS4.0

CVE-2025-40705 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:17 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 4:59 p.m.

5.1

CVSS4.0

CVE-2025-40704 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:17 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 4:59 p.m.

5.1

CVSS4.0

CVE-2025-40703 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:16 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 4:59 p.m.

5.1

CVSS4.0

CVE-2025-40702 - Cross-Site Scripting (XSS) vulnerability in OpenAtlas by ACDH-CH

Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an…

πŸ“… Published: Aug. 29, 2025, 11:16 a.m. πŸ”„ Last Modified: Sept. 2, 2025, 4:59 p.m.

6.5

CVSS3.1

CVE-2025-9217 - Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and '…

The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 via the 'used_svg' and 'used_images' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary fil…

πŸ“… Published: Aug. 29, 2025, 10:54 a.m. πŸ”„ Last Modified: April 20, 2026, 7:45 p.m.

8.1

CVSS3.1

CVE-2024-13342 - Booster for WooCommerce <= 7.2.4 - Unauthenticated Double Extension Arbitrary File Upload

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'add_files_to_order' function in all versions up to, and including, 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files with double e…

πŸ“… Published: Aug. 29, 2025, 10:54 a.m. πŸ”„ Last Modified: April 8, 2026, 4:55 p.m.

5.3

CVSS4.0

CVE-2025-4644 - User Session Fixation after Account Removal in PayloadCMS

A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created us…

πŸ“… Published: Aug. 29, 2025, 10:01 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2025-4643 - Lack of JWT Expiration after Log Out in PayloadCMS

Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker who has stolen or intercepted token to freely reuse it until expiration date (which is by default set to 2 hours, but can be changed). This issue has been fixed in version 3.44.0 …

πŸ“… Published: Aug. 29, 2025, 10:01 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4089 of 34,919
Β« previous page Β» next page
Filters