6.9

CVSS4.0

CVE-2025-8466 - code-projects Online Farm System forgot_passfarmer.php sql injection

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has bee…

📅 Published: Aug. 2, 2025, 8:32 a.m. 🔄 Last Modified: Aug. 5, 2025, 6:33 p.m.

6.4

CVSS3.1

CVE-2025-8391 - Magic Edge – Lite <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Pa…

The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acces…

📅 Published: Aug. 2, 2025, 8:24 a.m. 🔄 Last Modified: Aug. 4, 2025, 3:06 p.m.

6.1

CVSS3.1

CVE-2025-8400 - Image Gallery <= 1.0.0 - Reflected Cross-Site Scripting

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exec…

📅 Published: Aug. 2, 2025, 8:24 a.m. 🔄 Last Modified: Aug. 5, 2025, 11:39 a.m.

6.1

CVSS3.1

CVE-2025-6832 - All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Reflected Cross-…

The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible f…

📅 Published: Aug. 2, 2025, 8:24 a.m. 🔄 Last Modified: Aug. 5, 2025, 11:39 a.m.

6.4

CVSS3.1

CVE-2025-8399 - Mmm Unity Loader <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via attributes P…

The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level acce…

📅 Published: Aug. 2, 2025, 8:24 a.m. 🔄 Last Modified: Aug. 5, 2025, 11:39 a.m.

6.4

CVSS3.1

CVE-2025-8317 - Custom Word Cloud <= 0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via angle Param…

The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access a…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 4, 2025, 3:06 p.m.

6.4

CVSS3.1

CVE-2025-4588 - 360 Photo Spheres <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 4, 2025, 3:16 p.m.

6.4

CVSS3.1

CVE-2025-8212 - Medical Addon for Elementor <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewriter widget in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 5, 2025, 11:39 a.m.

5.3

CVSS3.1

CVE-2025-8152 - WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unau…

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_cta_status' and 'change_sticky_sidebar_name' functions in all versions up to, and including, 1.7.0. This makes it p…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 4, 2025, 3:18 p.m.

4.4

CVSS3.1

CVE-2025-6626 - ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization <= 3.10.4 - Authenticated (Adminis…

The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the API URL Setting in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenti…

📅 Published: Aug. 2, 2025, 7:24 a.m. 🔄 Last Modified: Aug. 5, 2025, 11:39 a.m.
Total resulsts: 304604
Page 60 of 30,461
« previous page » next page
Filters