9.9

CVSS3.1

CVE-2025-47663 - WordPress Hospital Management System plugin <= 47.0(20-11-2023) - Arbitrary File Upload vulnerabili…

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

8.1

CVSS3.1

CVE-2025-47670 - WordPress Social Login and Register plugin <= 7.6.10 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange WordPress Social Login and Register miniorange-login-openid allows PHP Local File Inclusion.This issue affects WordPress Social Login and Register: from n/a through <=…

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.6

CVSS3.1

CVE-2025-47671 - WordPress Binary MLM Plan plugin <= 3.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LETSCMS MLM Software Binary MLM Plan binary-mlm-plan allows SQL Injection.This issue affects Binary MLM Plan: from n/a through <= 3.0.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.1

CVSS3.1

CVE-2025-47672 - WordPress miniOrange Discord Integration plugin <= 2.2.2 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in miniOrange miniOrange Discord Integration miniorange-discord-integration allows PHP Local File Inclusion.This issue affects miniOrange Discord Integration: from n/a through <= 2.…

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-47673 - WordPress Arconix Shortcodes plugin <= 2.1.16 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Reflected XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.16.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-47678 - WordPress FunnelCockpit plugin <= 1.4.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit FunnelCockpit funnelcockpit allows Reflected XSS.This issue affects FunnelCockpit: from n/a through <= 1.4.3.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-47680 - WordPress xili-tidy-tags plugin <= 1.12.06 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup dev xili-tidy-tags xili-tidy-tags allows Reflected XSS.This issue affects xili-tidy-tags: from n/a through <= 1.12.06.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

10

CVSS3.1

CVE-2025-47687 - WordPress StoreKeeper for WooCommerce plugin <= 14.4.4 - Arbitrary File Upload Vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

8.8

CVSS3.1

CVE-2025-47690 - WordPress Lead Form Data Collection to CRM plugin <= 3.1 - Arbitrary Option Update to Privilege Esc…

Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Privilege Escalation.This issue affects Lead Form Data Collection to CRM: from n/a through <= 3.1.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-48241 - WordPress Verge3D plugin <= 4.9.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verge3D verge3d allows Reflected XSS.This issue affects Verge3D: from n/a through <= 4.9.3.

πŸ“… Published: May 23, 2025, 12:43 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.
Total resulsts: 347405
Page 5097 of 34,741
Β« previous page Β» next page
Filters