7.5

CVSS3.1

CVE-2025-0744 - Improper Access Control vulnerability in EmbedAI

an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay" endpoint.

πŸ“… Published: Jan. 30, 2025, 11:17 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

5.3

CVSS3.1

CVE-2025-0743 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint incl…

πŸ“… Published: Jan. 30, 2025, 11:16 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

5.8

CVSS3.1

CVE-2025-0742 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by changing the "FILE_ID" of the endpoint "/embedai/files/show/<FILE_ID>".

πŸ“… Published: Jan. 30, 2025, 11:14 a.m. πŸ”„ Last Modified: Oct. 8, 2025, 7:18 p.m.

5.8

CVSS3.1

CVE-2025-0741 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message".

πŸ“… Published: Jan. 30, 2025, 11:13 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 4:41 p.m.

8.6

CVSS3.1

CVE-2025-0740 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the β€œCHAT_ID” of the endpoint "/embedai/chats/load_messages?chat_id=<CHAT_ID>".

πŸ“… Published: Jan. 30, 2025, 11:11 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 4:41 p.m.

8.6

CVSS3.1

CVE-2025-0739 - Improper Access Control vulnerability in EmbedAI

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others users by changing the "SUSCBRIPTION_ID" param of the endpoint "/demos/embedai/subscriptions/show/<SUSCBRIPTION_ID>".

πŸ“… Published: Jan. 30, 2025, 11:10 a.m. πŸ”„ Last Modified: Oct. 10, 2025, 4:41 p.m.

6.1

CVSS3.1

CVE-2024-13706 - WP Image Uploader <= 1.0.1 - Reflected Cross-Site Scripting

The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc…

πŸ“… Published: Jan. 30, 2025, 11:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12409 - Simple:Press Forum <= 6.10.11 - Reflected Cross-Site Scripting

The Simple:Press Forum plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 6.10.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc…

πŸ“… Published: Jan. 30, 2025, 11:10 a.m. πŸ”„ Last Modified: April 8, 2026, 5:18 p.m.

7.3

CVSS3.1

CVE-2024-13453 - Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortc…

The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.6.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_…

πŸ“… Published: Jan. 30, 2025, 11:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-12524 - Clinked Client Portal <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for …

πŸ“… Published: Jan. 30, 2025, 11:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347256
Page 6719 of 34,726
Β« previous page Β» next page
Filters