6.1

CVSS3.1

CVE-2025-2635 - Digital License Manager <= 1.7.3 - Reflected Cross-Site Scripting via remove_query_arg Function

The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrar…

πŸ“… Published: March 25, 2025, 9:22 a.m. πŸ”„ Last Modified: April 21, 2026, 9:45 p.m.

6.4

CVSS3.1

CVE-2025-2542 - Your Simple SVG Support <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File…

The Your Simple SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and…

πŸ“… Published: March 25, 2025, 9:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-2755 - Open Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection out-of-bounds

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.en…

πŸ“… Published: March 25, 2025, 9 a.m. πŸ”„ Last Modified: July 17, 2025, 9:48 p.m.

5.3

CVSS4.0

CVE-2025-2754 - Open Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflow

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argu…

πŸ“… Published: March 25, 2025, 8:31 a.m. πŸ”„ Last Modified: July 17, 2025, 9:49 p.m.

5.3

CVSS4.0

CVE-2025-2753 - Open Asset Import Library Assimp LWS File LWSLoader.cpp MergeScenes out-of-bounds

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to…

πŸ“… Published: March 25, 2025, 8:31 a.m. πŸ”„ Last Modified: July 17, 2025, 9:50 p.m.

8.8

CVSS3.1

CVE-2025-2319 - EZ SQL Reports Shortcode Widget and DB Backup 4.11.13 - 5.25.08 - Cross-Site Request Forgery to Rem…

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.11.13 to 5.25.08. This is due to missing or incorrect nonce validation on the 'ELISQLREPORTS_menu' function. This makes it possible for unauthenticated attackers to execu…

πŸ“… Published: March 25, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS3.1

CVE-2024-13690 - WP Church Donation <= 1.7 - Unauthenticated Stored Cross-Site Scripting

The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submission parameters in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje…

πŸ“… Published: March 25, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-13731 - Alert Box Block – Display notice/alerts in the front end <= 1.1.3 - Authenticated (Contributor+) St…

The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert Box block in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This m…

πŸ“… Published: March 25, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-13710 - Estatebud – Properties & Listings <= 5.5.0 - Cross-Site Request Forgery to Settings Update

The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.0. This is due to missing or incorrect nonce validation on the 'estatebud_settings' page. This makes it possible for unauthenticated attackers to update t…

πŸ“… Published: March 25, 2025, 8:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-2510 - Frndzk Expandable Bottom Bar <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting vi…

The Frndzk Expandable Bottom Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'text' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level …

πŸ“… Published: March 25, 2025, 8:22 a.m. πŸ”„ Last Modified: April 21, 2026, 9:45 p.m.
Total resulsts: 349182
Page 6220 of 34,919
Β« previous page Β» next page
Filters