4.4
CVE-2025-5055 - Smart Forms <= 2.6.98 - Authenticated (Admin+) Stored Cross-Site Scripting
The Smart Forms β when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackβ¦
6.1
CVE-2025-3869 - 4stats <= 2.0.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the stats/stats.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious webβ¦
6.4
CVE-2024-13427 - Page Builder: Pagelayer β Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stoβ¦
The Page Builder: Pagelayer β Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makesβ¦
2.9
CVE-2025-48754 -
In the memory_pages crate 0.1.0 for Rust, division by zero can occur.
2.9
CVE-2025-48751 -
The process_lock crate 0.1.0 for Rust allows data races in unlock.
2.9
CVE-2025-48753 -
In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.
2.9
CVE-2025-48756 -
In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.
2.9
CVE-2025-48755 -
In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).
2.9
CVE-2025-48752 -
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
6.9
CVE-2025-5119 - Emlog Pro api_controller.php sql injection
A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The exploit has been discloseβ¦