5.3

CVSS4.0

CVE-2025-7943 - PHPGurukul Taxi Stand Management System search-autoortaxi.php cross site scripting

A vulnerability was found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/search-autoortaxi.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launcheโ€ฆ

๐Ÿ“… Published: July 21, 2025, 10:32 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:17 p.m.

4.4

CVSS3.1

CVE-2025-7486 - Ebook Store <= 5.8012 - Authenticated (Administrator+) Stored Cross-Site Scripting via Order Details

The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions up to, and including, 5.8012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inโ€ฆ

๐Ÿ“… Published: July 21, 2025, 10:21 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 2:45 p.m.

5.1

CVSS4.0

CVE-2025-7942 - PHPGurukul Taxi Stand Management System admin-profile.php cross site scripting

A vulnerability has been found in PHPGurukul Taxi Stand Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack can be lโ€ฆ

๐Ÿ“… Published: July 21, 2025, 10:02 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:17 p.m.

5.1

CVSS4.0

CVE-2025-7941 - PHPGurukul Time Table Generator System profile.php cross site scripting

A vulnerability, which was classified as problematic, was found in PHPGurukul Time Table Generator System 1.0. Affected is an unknown function of the file /admin/profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The โ€ฆ

๐Ÿ“… Published: July 21, 2025, 9:32 p.m. ๐Ÿ”„ Last Modified: July 29, 2025, 8:17 p.m.

4.8

CVSS4.0

CVE-2025-7940 - Genshin Albedo Cat House App com.house.auscat AndroidManifest.xml improper export of android applicโ€ฆ

A vulnerability was found in Genshin Albedo Cat House App 1.0.2 on Android. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.house.auscat. The manipulation leads to improper export of android applicaโ€ฆ

๐Ÿ“… Published: July 21, 2025, 9:02 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-54134 - HAX CMS NodeJs's Improper Error Handling Leads to Denial of Service

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the listFiles and saveFiles eโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:58 p.m. ๐Ÿ”„ Last Modified: July 30, 2025, 5:07 p.m.

4.3

CVSS3.1

CVE-2025-54129 - HAXiam allows for User Enumeration

HAXiam is a packaging wrapper for HAXcms which allows anyone to spawn their own microsite management platform. In versions 11.0.4 and below, the application returns a 200 response when requesting the data of a valid user and a 404 response when requesting the data of an invalid user. This can be usโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:53 p.m. ๐Ÿ”„ Last Modified: Aug. 22, 2025, 3:21 p.m.

7.2

CVSS4.0

CVE-2025-54128 - HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scripting

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-โ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:46 p.m. ๐Ÿ”„ Last Modified: July 30, 2025, 5:04 p.m.

9.3

CVSS4.0

CVE-2025-54127 - HAXcms's Insecure Default Configuration Leads to Unauthenticated Access

HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authenticationโ€ฆ

๐Ÿ“… Published: July 21, 2025, 8:36 p.m. ๐Ÿ”„ Last Modified: July 30, 2025, 5:03 p.m.

5.3

CVSS4.0

CVE-2025-7939 - jerryshensjf JPACookieShop ่›‹็ณ•ๅ•†ๅŸŽJPA็‰ˆ GoodsController.java addGoods unrestricted upload

A vulnerability was found in jerryshensjf JPACookieShop ่›‹็ณ•ๅ•†ๅŸŽJPA็‰ˆ 1.0. It has been classified as critical. Affected is the function addGoods of the file GoodsController.java. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.

๐Ÿ“… Published: July 21, 2025, 8:32 p.m. ๐Ÿ”„ Last Modified: Nov. 6, 2025, 4:01 p.m.
Total resulsts: 349182
Page 4557 of 34,919
ยซ previous page ยป next page
Filters