6.5

CVSS3.1

CVE-2025-39369 - WordPress Posts for Page plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sihibbs Posts for Page posts-for-page allows DOM-Based XSS.This issue affects Posts for Page: from n/a through <= 2.1.

πŸ“… Published: May 19, 2025, 4:35 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

5.3

CVSS3.1

CVE-2025-39368 - WordPress Rootspersona plugin <= 3.7.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in ed4becky Rootspersona rootspersona allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rootspersona: from n/a through <= 3.7.5.

πŸ“… Published: May 19, 2025, 4:33 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

6.9

CVSS4.0

CVE-2025-4940 - 1000 Projects Daily College Class Work Report Book admin_info.php sql injection

A vulnerability, which was classified as critical, has been found in 1000 Projects Daily College Class Work Report Book 1.0. This issue affects some unknown processing of the file /admin_info.php. The manipulation of the argument batch leads to sql injection. The attack may be initiated remotely. T…

πŸ“… Published: May 19, 2025, 4:31 p.m. πŸ”„ Last Modified: June 12, 2025, 4:24 p.m.

5.3

CVSS3.1

CVE-2025-39353 - WordPress Grand Restaurant WordPress theme <= 7.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Grand Restaurant: from n/a through <= 7.0.

πŸ“… Published: May 19, 2025, 4:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

4.3

CVSS3.1

CVE-2025-39351 - WordPress Grand Restaurant WordPress theme <= 7.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Cross Site Request Forgery.This issue affects Grand Restaurant: from n/a through <= 7.0.

πŸ“… Published: May 19, 2025, 4:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

7.5

CVSS3.1

CVE-2025-39364 - WordPress Product Category Slider for WooCommerce plugin <= 4.3.4 - Local File Inclusion vulnerabil…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginEver Product Category Slider for WooCommerce woo-category-slider-by-pluginever allows PHP Local File Inclusion.This issue affects Product Category Slider for WooCommerce: f…

πŸ“… Published: May 19, 2025, 4:28 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

8.8

CVSS3.1

CVE-2025-47576 - WordPress Bimber - Viral Magazine WordPress Theme theme <= 9.2.5 - Local File Inclusion vulnerabili…

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Bringthepixel Bimber - Viral Magazine WordPress Theme.This issue affects Bimber - Viral Magazine WordPress Theme: from n/a through 9.2.5.

πŸ“… Published: May 19, 2025, 4:23 p.m. πŸ”„ Last Modified: April 28, 2026, 7:32 p.m.

5.4

CVSS3.1

CVE-2025-47583 - WordPress Salon booking system plugin <= 10.16 - CSRF to Arbitrary Content Deletion vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16.

πŸ“… Published: May 19, 2025, 4:07 p.m. πŸ”„ Last Modified: April 23, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2025-32920 - WordPress TI WooCommerce Wishlist plugin <= 2.10.0 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0.

πŸ“… Published: May 19, 2025, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

6

CVSS3.1

CVE-2025-4876 - Hardcoded Key Revealed in ConnectWise Password Encryption Utility

ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to extract a hardcoded AES decryption key via reverse engineering. This key is embedded in plaintext within the binary and used in cryptographic operations without dynamic key management. Once obtained the…

πŸ“… Published: May 19, 2025, 4:04 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 1:42 a.m.
Total resulsts: 347061
Page 5123 of 34,707
Β« previous page Β» next page
Filters