5.3

CVSS3.1

CVE-2024-58135 - Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo ge…

Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default When creating a default app skeleton with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and…

📅 Published: May 3, 2025, 10:16 a.m. 🔄 Last Modified: Oct. 20, 2025, 8:15 p.m.

6.4

CVSS3.1

CVE-2025-3815 - SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above…

📅 Published: May 3, 2025, 7:22 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

7.3

CVSS3.1

CVE-2024-13738 - Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortco…

The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sh…

📅 Published: May 3, 2025, 2:21 a.m. 🔄 Last Modified: April 8, 2026, 4:49 p.m.

5.9

CVSS3.1

CVE-2025-4222 - Database Toolset <= 1.8.4 - Unauthenticated Sensitive Information Exposure via Backup Files

The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in a publicly accessible location. This makes it possible for unauthenticated attackers to extract sensitive data from database backup files.…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:34 p.m.

6.4

CVSS3.1

CVE-2025-3779 - Personizely <= 0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via widgetId Paramet…

The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all versions up to, and including, 0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

6.1

CVSS3.1

CVE-2025-4199 - Abundatrade Plugin <= 1.8.02 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to missing or incorrect nonce validation on the 'abundatrade' page. This makes it possible for unauthenticated attackers to update settings and inject ma…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

9.8

CVSS3.1

CVE-2025-3918 - Job Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action Function

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() withou…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: May 6, 2025, 3:03 p.m.

6.1

CVSS3.1

CVE-2025-4198 - Alink Tap <= 1.3.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the 'alink-tap' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web …

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:21 p.m.

6.4

CVSS3.1

CVE-2025-4168 - Subpage List <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.1

CVSS3.1

CVE-2025-4188 - Advanced Reorder Image Text Slider <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripti…

The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'reorder-simple-image-text-slider-setting' page. This makes it possible for unauthenticated …

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.
Total resulsts: 343919
Page 5036 of 34,392
« previous page » next page
Filters