4.4

CVSS3.1

CVE-2025-5055 - Smart Forms <= 2.6.98 - Authenticated (Admin+) Stored Cross-Site Scripting

The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.98 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

πŸ“… Published: May 24, 2025, 2:23 a.m. πŸ”„ Last Modified: April 21, 2026, 8:45 p.m.

6.1

CVSS3.1

CVE-2025-3869 - 4stats <= 2.0.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The 4stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the stats/stats.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web…

πŸ“… Published: May 24, 2025, 2:23 a.m. πŸ”„ Last Modified: April 21, 2026, 8:45 p.m.

6.4

CVSS3.1

CVE-2024-13427 - Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Sto…

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

πŸ“… Published: May 24, 2025, 1:41 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2.9

CVSS3.1

CVE-2025-48754 -

In the memory_pages crate 0.1.0 for Rust, division by zero can occur.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 8:34 p.m.

2.9

CVSS3.1

CVE-2025-48751 -

The process_lock crate 0.1.0 for Rust allows data races in unlock.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:21 p.m.

2.9

CVSS3.1

CVE-2025-48753 -

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:23 p.m.

2.9

CVSS3.1

CVE-2025-48756 -

In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 5:45 p.m.

2.9

CVSS3.1

CVE-2025-48755 -

In the spiral-rs crate 0.2.0 for Rust, allocation can be attempted for a ZST (zero-sized type).

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 8:38 p.m.

2.9

CVSS3.1

CVE-2025-48752 -

In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.

πŸ“… Published: May 24, 2025, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:22 p.m.

6.9

CVSS4.0

CVE-2025-5119 - Emlog Pro api_controller.php sql injection

A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code of the file /include/controller/api_controller.php. The manipulation of the argument tag leads to sql injection. The attack can be initiated remotely. The exploit has been disclose…

πŸ“… Published: May 23, 2025, 9 p.m. πŸ”„ Last Modified: June 10, 2025, 7:34 p.m.
Total resulsts: 349182
Page 5262 of 34,919
Β« previous page Β» next page
Filters