8.7
CVE-2025-9298 - Tenda M3 QuickIndex formQuickIndex stack-based overflow
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
8.7
CVE-2025-9297 - Tenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflow
A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performing manipulation of the argument Type results in stack-based buffer overflow. The attack can be initiated remotely. The exploit is now public and may be β¦
5.1
CVE-2025-9296 - Emlog Pro blogger.php unrestricted upload
A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admin/blogger.php?action=update_avatar. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been discloβ¦
6.4
CVE-2025-8064 - Bible SuperSearch <= 6.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via selector_β¦
The Bible SuperSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βselector_heightβ parameter in all versions up to, and including, 6.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-leβ¦
4.3
CVE-2025-47870 - Team invite ID leaked to team admin with no member invite privileges
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the teamβs invite id.
6.8
CVE-2025-49222 - Mattermost Shared Channel Upload Type Validation Bypass
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbβ¦
6.8
CVE-2025-8023 - Path Traversal in Template Upload Allows Uploading Files Outside Target Directory
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious fileβ¦
3.8
CVE-2025-53971 - Channel and Team Membership APIs inadvertently allow loss of Member privileges.
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.
3.5
CVE-2025-47700 - AI plugin APIs can be triggered using post actions
Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions
9.8
CVE-2025-8895 - WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy
The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. β¦