5.3

CVSS4.0

CVE-2025-2742 - zhijiantianya ruoyi-vue-pro Material Upload Interface upload-permanent path traversal

A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack caโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6:31 a.m. ๐Ÿ”„ Last Modified: July 15, 2025, 1:07 p.m.

6.9

CVSS4.0

CVE-2025-2740 - PHPGurukul Old Age Home Management System eligibility.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/eligibility.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit haโ€ฆ

๐Ÿ“… Published: March 25, 2025, 6:31 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 4:45 p.m.

6.1

CVSS3.1

CVE-2025-1798 - Design Comuni Italia < 1.1.2 - Unauthenticated Stored XSS

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Jan. 15, 2026, 7:49 p.m.

3.5

CVSS3.1

CVE-2025-1452 - Favorites < 2.3.5 - Admin+ Stored XSS

The Favorites WordPress plugin before 2.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: May 6, 2025, 7:59 p.m.

3.5

CVSS3.1

CVE-2025-0717 - Social Slider Feed < 2.2.9 - Admin+ Stored XSS

To exploit the vulnerability, it is necessary:

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: Jan. 13, 2026, 4:23 p.m.

4.7

CVSS3.1

CVE-2024-9770 - WP-Recall < 16.26.12 - Admin+ SQL Injection

The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 5:24 p.m.

7.1

CVSS3.1

CVE-2024-13863 - Stylish Google Sheet Reader < 4.1 - Reflected XSS

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 29, 2025, 5:35 p.m.

7.2

CVSS3.1

CVE-2024-13618 - Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated SSRF

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: June 20, 2025, 3:50 p.m.

8.6

CVSS3.1

CVE-2024-13617 - Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated Arbitrary File Download

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unauthenticated attackers to download arbitrary files from the server

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: June 20, 2025, 3:47 p.m.

3.5

CVSS3.1

CVE-2024-13123 - AFI < 1.100.0 - Admin+ Stored XSS

The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: March 25, 2025, 6 a.m. ๐Ÿ”„ Last Modified: April 1, 2025, 4:45 p.m.
Total resulsts: 342273
Page 5531 of 34,228
ยซ previous page ยป next page
Filters