7.5

CVSS3.1

CVE-2025-26894 - WordPress Coming Soon, Maintenance Mode plugin <= 1.1.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mobeen Abdullah Coming Soon, Maintenance Mode site-mode allows PHP Local File Inclusion.This issue affects Coming Soon, Maintenance Mode: from n/a through <= 1.1.1.

πŸ“… Published: April 15, 2025, 11:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-26889 - WordPress hockeydata LOS plugin <= 1.2.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hockeydata hockeydata LOS hockeydata-los allows PHP Local File Inclusion.This issue affects hockeydata LOS: from n/a through <= 1.2.4.

πŸ“… Published: April 15, 2025, 11:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

6.5

CVSS3.1

CVE-2025-26745 - WordPress RS Elements Elementor Addon plugin <= 1.1.5 - Stored Cross Site Scripting (XSS) vulnerabi…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSTheme RS Elements Elementor Addon rselements-lite allows Stored XSS.This issue affects RS Elements Elementor Addon: from n/a through <= 1.1.5.

πŸ“… Published: April 15, 2025, 11:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

6.5

CVSS3.1

CVE-2025-26744 - WordPress JetBlog plugin <= 2.4.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows DOM-Based XSS.This issue affects JetBlog: from n/a through <= 2.4.3.

πŸ“… Published: April 15, 2025, 11:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.1

CVSS3.1

CVE-2025-26743 - WordPress Advance WP Query Search Filter plugin <= 1.0.10 - Reflected Cross Site Scripting (XSS) vu…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TC.K Advance WP Query Search Filter advance-wp-query-search-filter allows Reflected XSS.This issue affects Advance WP Query Search Filter: from n/a through <= 1.0.10.

πŸ“… Published: April 15, 2025, 11:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

8.8

CVSS3.1

CVE-2025-26741 - WordPress Email Notifications for Updates <= 1.1.6 - Privilege Escalation Vulnerability

Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6.

πŸ“… Published: April 15, 2025, 11:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:25 p.m.

7.5

CVSS3.1

CVE-2025-32929 - WordPress Barcode Generator for WooCommerce plugin <= 2.0.4 - Arbitrary Content Deletion vulnerabil…

Missing Authorization vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Generator for WooCommerce embedding-barcodes-into-product-pages-and-orders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Barcode Generator for WooCommerce: from n/a through …

πŸ“… Published: April 15, 2025, 11:58 a.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

7.1

CVSS3.1

CVE-2025-26992 - WordPress Landing Page Cat plugin <= 1.7.8 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue affects Landing Page Cat: from n/a through <= 1.7.8.

πŸ“… Published: April 15, 2025, 11:58 a.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

3.7

CVSS3.1

CVE-2025-32943 - PeerTube HLS Video Files Path Traversal

The vulnerability allows any authenticated user to leak the contents of arbitrary β€œ.m3u8” files from the PeerTube server due to a path traversal in the HLS endpoint.

πŸ“… Published: April 15, 2025, 10:24 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 4:52 p.m.

5.5

CVSS4.0

CVE-2025-1688 - System configuration password reset

Milestone Systems has discovered a security vulnerability in Milestone XProtect installer that resets system configuration password after the upgrading from older versions using specific installers. The system configuration password is an additional, optional protection that is enabled on the Ma…

πŸ“… Published: April 15, 2025, 10:13 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346533
Page 5617 of 34,654
Β« previous page Β» next page
Filters