7.5

CVSS3.0

CVE-2025-24289 -

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. The plugin is disabled by default.

πŸ“… Published: June 29, 2025, 7:25 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

5.1

CVSS4.0

CVE-2025-6868 - SourceCodester Simple Company Website manage.php sql injection

A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit ha…

πŸ“… Published: June 29, 2025, 7:02 p.m. πŸ”„ Last Modified: July 8, 2025, 2:37 p.m.

5.1

CVSS4.0

CVE-2025-6867 - SourceCodester Simple Company Website manage.php sql injection

A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has bee…

πŸ“… Published: June 29, 2025, 6:32 p.m. πŸ”„ Last Modified: July 8, 2025, 2:38 p.m.

5.3

CVSS4.0

CVE-2025-6866 - code-projects Simple Forum forum_downloadfile.php path traversal

A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been dis…

πŸ“… Published: June 29, 2025, 6:02 p.m. πŸ”„ Last Modified: Oct. 23, 2025, 8:06 p.m.

5.3

CVSS4.0

CVE-2025-6865 - DaiCuo index cross-site request forgery

A vulnerability, which was classified as problematic, was found in DaiCuo up to 1.3.13. This affects an unknown part of the file /admin.php/addon/index. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…

πŸ“… Published: June 29, 2025, 5:02 p.m. πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-6864 - SeaCMS admin_type.php cross-site request forgery

A vulnerability, which was classified as problematic, has been found in SeaCMS up to 13.2. Affected by this issue is some unknown functionality of the file /admin_type.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to t…

πŸ“… Published: June 29, 2025, 4 p.m. πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.

6.9

CVSS4.0

CVE-2025-6863 - PHPGurukul Local Services Search Engine Management System edit-category-detail.php sql injection

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-category-detail.php. The manipulation of the argument editid leads to sql injection. The attack can b…

πŸ“… Published: June 29, 2025, 3 p.m. πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2025-6862 - SourceCodester Best Salon Management System edit_plan.php sql injection

A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the file /panel/edit_plan.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has b…

πŸ“… Published: June 29, 2025, 2:31 p.m. πŸ”„ Last Modified: July 1, 2025, 1:07 p.m.

5.3

CVSS4.0

CVE-2025-6861 - SourceCodester Best Salon Management System add_plan.php sql injection

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /panel/add_plan.php. The manipulation of the argument plan_name/description/duration_days/price leads to sql injection. The attack may …

πŸ“… Published: June 29, 2025, 2 p.m. πŸ”„ Last Modified: July 1, 2025, 1:13 p.m.

5.3

CVSS4.0

CVE-2025-6860 - SourceCodester Best Salon Management System staff_commision.php sql injection

A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /panel/staff_commision.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be initiated remote…

πŸ“… Published: June 29, 2025, 1 p.m. πŸ”„ Last Modified: July 1, 2025, 1:30 p.m.
Total resulsts: 343968
Page 4321 of 34,397
Β« previous page Β» next page
Filters