4.4

CVSS3.1

CVE-2025-8080 - Alobaidi Captcha <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin S…

The Alobaidi Captcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permiss…

📅 Published: Aug. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 21, 2026, 7:30 p.m.

4.3

CVSS3.1

CVE-2025-8091 - EventON Lite <= 2.4.7 - Authenticated (Contributor+) Information Disclosure

The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to ex…

📅 Published: Aug. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 21, 2026, 7:30 p.m.

9.8

CVSS3.1

CVE-2025-7778 - Icons Factory <= 1.6.12 - Missing Authorization to Unauthenticated Arbitrary File Deletion via dele…

The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unauthenticated attackers to to delete arbitrary…

📅 Published: Aug. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

6.1

CVSS3.1

CVE-2025-7688 - Add User Meta <= 1.0.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the 'add-user-meta' page. This makes it possible for unauthenticated attackers to update settings and inject malici…

📅 Published: Aug. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

7.5

CVSS3.1

CVE-2025-7641 - Assistant for NextGEN Gallery <= 1.0.9 - Unauthenticated Arbitrary Directory Deletion

The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in the /wp-json/nextgenassistant/v1.0.0/control REST endpoint in all versions up to, and including, 1.0.9. This makes it possible for unauthenticated attacke…

📅 Published: Aug. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

7.5

CVSS3.1

CVE-2025-7650 - BizCalendar Web <= 1.1.0.53 - Authenticated (Contributor+) Local File Inclusion

The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.0.53 via the 'bizcalv' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the serve…

📅 Published: Aug. 15, 2025, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 2:30 p.m.

6.9

CVSS4.0

CVE-2025-9022 - SourceCodester Online Bank Management System statements.php sql injection

A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknown processing of the file /bank/statements.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely.

📅 Published: Aug. 15, 2025, 8:02 a.m. 🔄 Last Modified: Aug. 21, 2025, 4:17 p.m.

6.9

CVSS4.0

CVE-2025-9021 - SourceCodester Online Bank Management System transfer.php sql injection

A vulnerability was determined in SourceCodester Online Bank Management System up to 1.0. This vulnerability affects unknown code of the file /bank/transfer.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely.

📅 Published: Aug. 15, 2025, 8:02 a.m. 🔄 Last Modified: Aug. 21, 2025, 4:21 p.m.

2

CVSS4.0

CVE-2025-9020 - PX4 PX4-Autopilot Mavlink Shell Closing mavlink_receiver.cpp handle_message_serial_control use afte…

A vulnerability was found in PX4 PX4-Autopilot up to 1.15.4. This issue affects the function MavlinkReceiver::handle_message_serial_control of the file src/modules/mavlink/mavlink_receiver.cpp of the component Mavlink Shell Closing Handler. The manipulation of the argument _mavlink_shell leads to u…

📅 Published: Aug. 15, 2025, 7:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2025-8604 - WP Table Builder – WordPress Table Plugin <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Sit…

The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wptb shortcode in all versions up to, and including, 2.0.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

📅 Published: Aug. 15, 2025, 7:24 a.m. 🔄 Last Modified: April 20, 2026, 8 p.m.
Total resulsts: 349182
Page 4261 of 34,919
« previous page » next page
Filters