5.4

CVSS3.1

CVE-2025-27445 - Extension - rsjoomla.com - A path traversal vulnerability RSFirewall component 2.9.7 - 3.1.5 for Jo…

A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, al…

πŸ“… Published: June 5, 2025, 1:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-30084 - Extension - rsjoomla.com - Reflected XSS vulnerability RSMail! component 1.19.20-1.22.26 for Joomla

A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or o…

πŸ“… Published: June 5, 2025, 1:20 p.m. πŸ”„ Last Modified: Aug. 13, 2025, 3:14 p.m.

5.3

CVSS4.0

CVE-2025-5660 - PHPGurukul Complaint Management System register-complaint.php sql injection

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 2.0. Affected by this issue is some unknown functionality of the file /user/register-complaint.php. The manipulation of the argument noc leads to sql injection. The attack may be launched rem…

πŸ“… Published: June 5, 2025, 1 p.m. πŸ”„ Last Modified: June 6, 2025, 6:42 p.m.

5.3

CVSS4.0

CVE-2025-5659 - PHPGurukul Complaint Management System profile.php sql injection

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /user/profile.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit…

πŸ“… Published: June 5, 2025, 1 p.m. πŸ”„ Last Modified: June 6, 2025, 6:42 p.m.

5.3

CVSS4.0

CVE-2025-5658 - PHPGurukul Complaint Management System updatecomplaint.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/updatecomplaint.php. The manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has …

πŸ“… Published: June 5, 2025, 12:31 p.m. πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.

5.3

CVSS4.0

CVE-2025-5657 - PHPGurukul Complaint Management System manage-users.php sql injection

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument uid leads to sql injection. The attack may be initiated remotely. The exploit has …

πŸ“… Published: June 5, 2025, noon πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.

8.8

CVSS3.1

CVE-2011-10007 - File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` enco…

File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a…

πŸ“… Published: June 5, 2025, 11:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-5656 - PHPGurukul Complaint Management System edit-category.php sql injection

A vulnerability was found in PHPGurukul Complaint Management System 2.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-category.php. The manipulation of the argument description leads to sql injection. The attack can be initiated remotely. The exp…

πŸ“… Published: June 5, 2025, 11:31 a.m. πŸ”„ Last Modified: June 10, 2025, 3:02 p.m.

6.4

CVSS3.1

CVE-2025-5341 - Forminator <= 1.44.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via id an…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜id' and 'data-size’ parameters in all versions up to, and including, 1.44.1 due to insufficient input sanitization and output escaping. This makes it po…

πŸ“… Published: June 5, 2025, 11:15 a.m. πŸ”„ Last Modified: April 22, 2026, 1:30 a.m.

8.8

CVSS3.1

CVE-2025-5701 - HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update

The HyperComments plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the hc_request_handler function in all versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to u…

πŸ“… Published: June 5, 2025, 11:15 a.m. πŸ”„ Last Modified: April 22, 2026, 3 p.m.
Total resulsts: 346717
Page 4919 of 34,672
Β« previous page Β» next page
Filters