6.5

CVSS3.1

CVE-2025-24764 - WordPress (Simply) Guest Author Name plugin <= 4.36 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) Guest Author Name guest-author-name allows DOM-Based XSS.This issue affects (Simply) Guest Author Name: from n/a through <= 4.36.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 2:03 p.m.

5.3

CVSS3.1

CVE-2025-24757 - WordPress uDesign theme <= 4.11.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.2.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

5.3

CVSS3.1

CVE-2025-24748 - WordPress Avada theme <= 7.11.10 - Broken Access Control vulnerability

Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

5.9

CVSS3.1

CVE-2025-24735 - WordPress Chatra Live Chat + ChatBot + Cart Saver plugin <= 1.0.11 - Cross Site Scripting (XSS) Vul…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live Chat + ChatBot + Cart Saver allows Stored XSS. This issue affects Chatra Live Chat + ChatBot + Cart Saver: from n/a through 1.0.11.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-23972 - WordPress Contact Form 7 reCAPTCHA plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Brian S. Reed Contact Form 7 reCAPTCHA contact-form-7-recaptcha allows Cross Site Request Forgery.This issue affects Contact Form 7 reCAPTCHA: from n/a through <= 1.2.0.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.

4.3

CVSS3.1

CVE-2025-53569 - WordPress Trust Payments Gateway for WooCommerce (JavaScript Library) plugin <= 1.3.6 - Cross Site …

Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Library) trust-payments-gateway-3ds2 allows Cross Site Request Forgery.This issue affects Trust Payments Gateway for WooCommerce (JavaScript Library): from n/a through <= 1.3.6.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

4.3

CVSS3.1

CVE-2025-53568 - WordPress Radio Station plugin <= 2.5.12 - Cross Site Request Forgery (CSRF) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station allows Cross Site Request Forgery.This issue affects Radio Station: from n/a through <= 2.5.12.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

6.5

CVSS3.1

CVE-2025-53566 - WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 7.8 - Cross Site Scripting (XSS) Vuln…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Stored XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 7.8.

πŸ“… Published: July 4, 2025, 8:42 a.m. πŸ”„ Last Modified: April 23, 2026, 2:13 p.m.

6.5

CVSS3.1

CVE-2024-9453 - Jenkins-image: sensitive data disclosure when using openshift jenkins image

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they…

πŸ“… Published: July 4, 2025, 8:31 a.m. πŸ”„ Last Modified: Dec. 12, 2025, 1:46 p.m.

5.3

CVSS4.0

CVE-2025-32918 - Livestatus injection in autocomplete endpoint

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.

πŸ“… Published: July 4, 2025, 8:12 a.m. πŸ”„ Last Modified: Aug. 22, 2025, 1:29 p.m.
Total resulsts: 346551
Page 4526 of 34,656
Β« previous page Β» next page
Filters