3.5

CVSS3.1

CVE-2024-10560 - Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS

The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: March 25, 2025, 6 a.m. πŸ”„ Last Modified: April 3, 2025, 5:37 p.m.

3.5

CVSS3.1

CVE-2024-10554 - WP-Advanced-Search < 3.3.9.3 - Admin+ Stored XSS

The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite se…

πŸ“… Published: March 25, 2025, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 7:18 p.m.

5.9

CVSS3.1

CVE-2024-10472 - Stylish Price List < 7.1.12 - Contributor+ Stored XSS

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: March 25, 2025, 6 a.m. πŸ”„ Last Modified: May 15, 2025, 7:24 p.m.

5.9

CVSS3.1

CVE-2024-10105 - Jobs for WordPress < 2.7.11 - Contributor+ Stored XSS

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: March 25, 2025, 6 a.m. πŸ”„ Last Modified: April 2, 2025, 5:33 p.m.

8.4

CVSS4.0

CVE-2024-10210 - Path traversal in APROL Web Portal

An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system.

πŸ“… Published: March 25, 2025, 5:32 a.m. πŸ”„ Last Modified: March 31, 2025, 6 p.m.

6.9

CVSS4.0

CVE-2025-2737 - PHPGurukul Old Age Home Management System contactus.php sql injection

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to initiate the attack remotely. The explo…

πŸ“… Published: March 25, 2025, 5:31 a.m. πŸ”„ Last Modified: May 6, 2025, 7:39 p.m.

5.3

CVSS3.1

CVE-2025-2224 - Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishing

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible fo…

πŸ“… Published: March 25, 2025, 5:22 a.m. πŸ”„ Last Modified: March 31, 2025, 6:18 p.m.

6.4

CVSS3.1

CVE-2025-0845 - DesignThemes Core Features <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Sh…

The DesignThemes Core Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contr…

πŸ“… Published: March 25, 2025, 5:22 a.m. πŸ”„ Last Modified: July 13, 2025, 11:07 a.m.

6.9

CVSS4.0

CVE-2025-2736 - PHPGurukul Old Age Home Management System bwdates-report-details.php sql injection

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/bwdates-report-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be launched rem…

πŸ“… Published: March 25, 2025, 5 a.m. πŸ”„ Last Modified: May 15, 2025, 7:29 p.m.

6.9

CVSS4.0

CVE-2025-2735 - PHPGurukul Old Age Home Management System add-services.php sql injection

A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-services.php. The manipulation of the argument sertitle leads to sql injection. The attack can be launched re…

πŸ“… Published: March 25, 2025, 5 a.m. πŸ”„ Last Modified: May 15, 2025, 7:32 p.m.
Total resulsts: 342358
Page 5542 of 34,236
Β« previous page Β» next page
Filters