7.5
CVE-2025-26730 - WordPress Macro Calculator with Admin Email Optin & Data plugin <= 1.0 - Multiple Vulnerabilities vโฆ
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro Calculator with Admin Email Optin & Data: from n/a through 1.0.
6.5
CVE-2025-22269 - WordPress Real Testimonials plugin <= 3.1.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.
6.5
CVE-2025-22268 - WordPress Uncanny Toolkit for LearnDash plugin <= 3.7.0.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.1.
7.1
CVE-2025-22263 - WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Gallery allows Reflected XSS. This issue affects Global Gallery: from n/a through 8.8.0.
6.9
CVE-2025-31147 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
6.9
CVE-2025-31360 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
6.9
CVE-2025-30512 - Growatt Cloud portal External Control of System or Configuration Setting
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).
6.9
CVE-2025-27927 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.
9.3
CVE-2025-24297 - Growatt Cloud portal Cross-site Scripting
Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces of the web portal.
9.3
CVE-2025-30510 - Growatt Cloud portal Insufficient Type Distinction
An attacker can upload an arbitrary file instead of a plant image.