7.1
CVE-2025-26746 - WordPress Advanced Custom Fields: Link Picker Field plugin <= 1.2.8 - Reflected Cross Site Scriptinβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in caalami Advanced Custom Fields: Link Picker Field acf-link-picker-field allows Reflected XSS.This issue affects Advanced Custom Fields: Link Picker Field: from n/a through <= 1.2.8.
6.5
CVE-2025-26740 - WordPress SpaBiz plugin <= 1.0.18 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware SpaBiz spabiz allows DOM-Based XSS.This issue affects SpaBiz: from n/a through <= 1.0.18.
7.5
CVE-2025-26730 - WordPress Macro Calculator with Admin Email Optin & Data plugin <= 1.0 - Multiple Vulnerabilities vβ¦
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro Calculator with Admin Email Optin & Data: from n/a through 1.0.
6.5
CVE-2025-22269 - WordPress Real Testimonials plugin <= 3.1.6 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Stored XSS.This issue affects Real Testimonials: from n/a through <= 3.1.6.
6.5
CVE-2025-22268 - WordPress Uncanny Toolkit for LearnDash plugin <= 3.7.0.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.1.
7.1
CVE-2025-22263 - WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Global Gallery allows Reflected XSS. This issue affects Global Gallery: from n/a through 8.8.0.
6.9
CVE-2025-31147 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Unauthenticated attackers can query information about total energy consumed by EV chargers of arbitrary users.
6.9
CVE-2025-31360 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users.
6.9
CVE-2025-30512 - Growatt Cloud portal External Control of System or Configuration Setting
Unauthenticated attackers can send configuration settings to device and possible perform physical actions remotely (e.g., on/off).
6.9
CVE-2025-27927 - Growatt Cloud portal Authorization Bypass Through User-Controlled Key
An unauthenticated attackers can obtain a list of smart devices by knowing a valid username through an unprotected API.