7.1
CVE-2025-23425 - WordPress Marekkis Watermark plugin <= 0.9.4 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis Watermark marekkis-watermark allows Reflected XSS.This issue affects Marekkis Watermark: from n/a through <= 0.9.4.
8.8
CVE-2025-26999 - WordPress ProfileGrid Plugin <= 5.9.4.3 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.3.
9.3
CVE-2025-1875 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.
9.3
CVE-2025-1874 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.
9.3
CVE-2025-1873 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.
9.3
CVE-2025-1872 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.
9.3
CVE-2025-1871 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.
9.3
CVE-2025-1870 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.
9.3
CVE-2025-1869 - SQL injection vulnerability in 101news
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.
5.3
CVE-2024-10925 - Authorization Bypass Through User-Controlled Key in GitLab
A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows a Guest user to read Security policy YAML