6.9

CVSS4.0

CVE-2025-4226 - PHPGurukul/Campcodes Cyber Cafe Management System add-computer.php sql injection

A vulnerability classified as critical has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. This affects an unknown part of the file /add-computer.php. The manipulation of the argument compname/comploc leads to sql injection. It is possible to initiate the attack remotely. The e…

📅 Published: May 3, 2025, 11 a.m. 🔄 Last Modified: May 30, 2025, 10:15 a.m.

5.3

CVSS3.1

CVE-2024-58135 - Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo ge…

Mojolicious versions from 7.28 for Perl will generate weak HMAC session cookie secrets via "mojo generate app" by default When creating a default app skeleton with the "mojo generate app" tool, a weak secret is written to the application's configuration file using the insecure rand() function, and…

📅 Published: May 3, 2025, 10:16 a.m. 🔄 Last Modified: Oct. 20, 2025, 8:15 p.m.

6.4

CVSS3.1

CVE-2025-3815 - SurveyJS <= 1.12.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.12.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above…

📅 Published: May 3, 2025, 7:22 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

7.3

CVSS3.1

CVE-2024-13738 - Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortco…

The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sh…

📅 Published: May 3, 2025, 2:21 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2025-4222 - Database Toolset <= 1.8.4 - Unauthenticated Sensitive Information Exposure via Backup Files

The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in a publicly accessible location. This makes it possible for unauthenticated attackers to extract sensitive data from database backup files.…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

6.4

CVSS3.1

CVE-2025-3779 - Personizely <= 0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via widgetId Paramet…

The Personizely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘widgetId’ parameter in all versions up to, and including, 0.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 21, 2026, 9 p.m.

6.1

CVSS3.1

CVE-2025-4199 - Abundatrade Plugin <= 1.8.02 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to missing or incorrect nonce validation on the 'abundatrade' page. This makes it possible for unauthenticated attackers to update settings and inject ma…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 21, 2026, 9 p.m.

9.8

CVSS3.1

CVE-2025-3918 - Job Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action Function

The Job Listings plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the register_action() function in versions 0.1 to 0.1.1. The plugin’s registration handler reads the client-supplied $_POST['user_role'] and passes it directly to wp_insert_user() withou…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-4198 - Alink Tap <= 1.3.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the 'alink-tap' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web …

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 20, 2026, 11 p.m.

6.4

CVSS3.1

CVE-2025-4168 - Subpage List <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Subpage List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'subpages' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: May 3, 2025, 1:43 a.m. 🔄 Last Modified: April 21, 2026, 9 p.m.
Total resulsts: 347061
Page 5350 of 34,707
« previous page » next page
Filters