9.9

CVSS3.1

CVE-2025-26892 - WordPress Celestial Aura plugin <= 2.2 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Celestial Aura allows Using Malicious Files.This issue affects Celestial Aura: from n/a through 2.2.

πŸ“… Published: May 19, 2025, 6:06 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.

9.9

CVSS3.1

CVE-2025-26872 - WordPress Eximius theme <= 2.2 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in dkszone Eximius allows Using Malicious Files.This issue affects Eximius: from n/a through 2.2.

πŸ“… Published: May 19, 2025, 6:04 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.

7.5

CVSS3.1

CVE-2025-26735 - WordPress Grip theme <= 1.0.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Candid themes Grip.This issue affects Grip: from n/a through 1.0.9.

πŸ“… Published: May 19, 2025, 6:01 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.

5.4

CVSS3.1

CVE-2025-22287 - WordPress LTL Freight Quotes – FreightQuote Edition plugin <= 2.3.11 - Broken Access Control vulner…

Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition ltl-freight-quotes-freightquote-edition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a through <= 2.3.11.

πŸ“… Published: May 19, 2025, 5:56 p.m. πŸ”„ Last Modified: April 29, 2026, 9:56 a.m.

9.9

CVSS3.0

CVE-2025-47282 - Malicious google credential in DNS secret can lead to privilege escalation

Gardener External DNS Management is an environment to manage external DNS entries for a kubernetes cluster. A security vulnerability was discovered in Gardener's External DNS Management prior to version 0.23.6 that could allow a user with administrative privileges for a Gardener project or a user w…

πŸ“… Published: May 19, 2025, 5:53 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-39448 - WordPress JetElements For Elementor plugin <= 2.7.4.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.4.1.

πŸ“… Published: May 19, 2025, 5:33 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

6.5

CVSS3.1

CVE-2025-39450 - WordPress JetTabs plugin <= 2.2.7 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.7.

πŸ“… Published: May 19, 2025, 5:32 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

4.3

CVSS3.1

CVE-2025-39454 - WordPress Name Directory plugin <= 1.30.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.30.0.

πŸ“… Published: May 19, 2025, 5:31 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

5.3

CVSS3.1

CVE-2025-39460 - WordPress Eduma theme <= 5.6.4 - Broken Access Control vulnerability

Missing Authorization vulnerability in ThimPress Eduma eduma allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eduma: from n/a through <= 5.6.4.

πŸ“… Published: May 19, 2025, 5:30 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

7.6

CVSS3.1

CVE-2025-43833 - WordPress Absolute Links plugin <= 1.1.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Amir Helzer Absolute Links absolute-links allows Blind SQL Injection.This issue affects Absolute Links: from n/a through <= 1.1.1.

πŸ“… Published: May 19, 2025, 5:29 p.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.
Total resulsts: 349182
Page 5332 of 34,919
Β« previous page Β» next page
Filters