6.9

CVSS4.0

CVE-2025-8469 - SourceCodester Online Hotel Reservation System deletegallery.php sql injection

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit hasโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 5:02 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 6:25 p.m.

6.9

CVSS4.0

CVE-2025-8468 - code-projects Wazifa System reset.php sql injection

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /controllers/reset.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has bโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 2:32 p.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 6:32 p.m.

6.4

CVSS3.1

CVE-2025-7500 - Ocean Social Sharing <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level accessโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 11:23 a.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 3:16 p.m.

9.8

CVSS3.1

CVE-2025-7710 - Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is due to the plugin not properly restricting a claimed identity while authenticating with Facebook. This makes it possible for unauthenticated attackers tโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 11:23 a.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 11:39 a.m.

6.9

CVSS4.0

CVE-2025-8467 - code-projects Wazifa System regcontrol.php sql injection

A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /controllers/regcontrol.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. โ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 11:02 a.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 6:33 p.m.

4.3

CVSS3.1

CVE-2025-8488 - Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) <= 2.4.6 - Missing Authoโ€ฆ

The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_hfe_compatibility_option_callback ()function in all versions up to, and including, 2.4.6. This makes iโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 11:38 a.m.

5.3

CVSS3.1

CVE-2025-6722 - BitFire <= 4.5 - Unauthenticated Information Exposure

The BitFire Security โ€“ Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any accessโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 9:23 a.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 8:15 p.m.

6.9

CVSS4.0

CVE-2025-8466 - code-projects Online Farm System forgot_passfarmer.php sql injection

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an unknown function of the file /forgot_passfarmer.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has beeโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 8:32 a.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 6:33 p.m.

6.4

CVSS3.1

CVE-2025-8391 - Magic Edge โ€“ Lite <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Paโ€ฆ

The Magic Edge โ€“ Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜heightโ€™ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level accesโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 8:24 a.m. ๐Ÿ”„ Last Modified: Aug. 4, 2025, 3:06 p.m.

6.1

CVSS3.1

CVE-2025-8400 - Image Gallery <= 1.0.0 - Reflected Cross-Site Scripting

The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execโ€ฆ

๐Ÿ“… Published: Aug. 2, 2025, 8:24 a.m. ๐Ÿ”„ Last Modified: Aug. 5, 2025, 11:39 a.m.
Total resulsts: 304671
Page 66 of 30,468
ยซ previous page ยป next page
Filters