5.4

CVSS3.1

CVE-2025-3056 - Download Manager <= 3.3.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.3.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above…

πŸ“… Published: April 18, 2025, 8:21 a.m. πŸ”„ Last Modified: April 21, 2026, 9:30 p.m.

4.8

CVSS3.1

CVE-2025-2162 - MapPress Maps for WordPress < 2.94.10 - Admin+ Stored XSS

The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: April 18, 2025, 6 a.m. πŸ”„ Last Modified: May 28, 2025, 5:43 p.m.

9.8

CVSS3.1

CVE-2025-1863 - Insecure default settings for recorder products

Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all functions related to…

πŸ“… Published: April 18, 2025, 5:55 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-3783 - SourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted upload

A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-product.php. The manipulation of the argument Avatar leads to unrestricted upload. The attack can be launc…

πŸ“… Published: April 18, 2025, 5:31 a.m. πŸ”„ Last Modified: April 9, 2026, 7:50 p.m.

6.1

CVSS3.1

CVE-2025-3598 - Coupon Affiliates – Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via …

The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the commission_summary parameter in all versions up to, and including, .6.3.0 due to insufficient input sanitization and output escaping. This makes it possible for unau…

πŸ“… Published: April 18, 2025, 5:22 a.m. πŸ”„ Last Modified: April 22, 2026, 5:45 p.m.

7.1

CVSS3.1

CVE-2025-39469 - WordPress Modal Survey plugin <= 2.0.2.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pantherius Modal Survey modal-survey.This issue affects Modal Survey: from n/a through <= 2.0.2.0.1.

πŸ“… Published: April 18, 2025, 4:31 a.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

8.1

CVSS3.1

CVE-2025-39470 - WordPress Ivy School theme <= 1.6.0 - Local File Inclusion Vulnerability

Path Traversal: '.../...//' vulnerability in ThimPress Ivy School ivy-school allows PHP Local File Inclusion.This issue affects Ivy School: from n/a through <= 1.6.0.

πŸ“… Published: April 18, 2025, 4:30 a.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

9.3

CVSS3.1

CVE-2025-39471 - WordPress Modal Survey plugin <= 2.0.2.0.1 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal Survey modal-survey.This issue affects Modal Survey: from n/a through <= 2.0.2.0.1.

πŸ“… Published: April 18, 2025, 4:27 a.m. πŸ”„ Last Modified: April 23, 2026, 3:29 p.m.

9.8

CVSS3.1

CVE-2025-42599 -

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

πŸ“… Published: April 18, 2025, 3:52 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 6:28 p.m.

4.4

CVSS3.1

CVE-2025-2613 - Login Manager – Design Login Page, View Login Activity, Limit Login Attempts <= 2.0.5 - Authenticat…

The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom logo and background URLs in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: April 18, 2025, 1:44 a.m. πŸ”„ Last Modified: April 20, 2026, 11:15 p.m.
Total resulsts: 349182
Page 5721 of 34,919
Β« previous page Β» next page
Filters