7.1

CVSS3.1

CVE-2025-39372 - WordPress WordPress Events Calendar Registration & Tickets plugin <= 2.6.0 - Reflected Cross Site S…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0.

πŸ“… Published: May 19, 2025, 7:38 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

10

CVSS3.1

CVE-2025-39380 - WordPress Hospital Management System plugin <= 47.0(20-11-2023) - Arbitrary File Upload vulnerabili…

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023).

πŸ“… Published: May 19, 2025, 7:36 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

9.3

CVSS3.1

CVE-2025-39386 - WordPress Hospital Management System plugin <= 47.0(20-11-2023) - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System hospital-management allows SQL Injection.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023).

πŸ“… Published: May 19, 2025, 7:34 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

9.3

CVSS3.1

CVE-2025-39389 - WordPress AnalyticsWP <= 2.1.2 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins AnalyticsWP allows SQL Injection.This issue affects AnalyticsWP: from n/a through 2.1.2.

πŸ“… Published: May 19, 2025, 7:31 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-39392 - WordPress WPAMS plugin <= 44.0 (17-08-2023) - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apartment-management allows Reflected XSS.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023).

πŸ“… Published: May 19, 2025, 7:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

9.9

CVSS4.0

CVE-2025-47949 - samlify SAML Signature Wrapping attack

samlify is a Node.js library for SAML single sign-on. A Signature Wrapping attack has been found in samlify prior to version 2.10.0, allowing an attacker to forge a SAML Response to authenticate as any user. An attacker would need a signed XML document by the identity provider. Version 2.10.0 fixes…

πŸ“… Published: May 19, 2025, 7:28 p.m. πŸ”„ Last Modified: Sept. 19, 2025, 5:32 p.m.

7.1

CVSS3.1

CVE-2025-39393 - WordPress Hospital Management System plugin <= 47.0(20-11-2023) - Cross Site Scripting (XSS) vulner…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital Management System hospital-management allows Reflected XSS.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023).

πŸ“… Published: May 19, 2025, 7:28 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

9.3

CVSS3.1

CVE-2025-39395 - WordPress WPAMS plugin <= 44.0 (17-08-2023) - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management allows SQL Injection.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023).

πŸ“… Published: May 19, 2025, 7:27 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

10

CVSS3.1

CVE-2025-39401 - WordPress WPAMS plugin <= 44.0 (17-08-2023) - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023).

πŸ“… Published: May 19, 2025, 7:26 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

6.1

CVSS3.1

CVE-2025-47946 - symfony/ux-live-component and symfony/ux-twig-component vulnerable to unsanitized HTML attribute in…

Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly witho…

πŸ“… Published: May 19, 2025, 7:25 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 5328 of 34,919
Β« previous page Β» next page
Filters