5.3
CVE-2025-0558 - TDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injection
A vulnerability classified as critical was found in TDuckCloud tduck-platform up to 4.0. This vulnerability affects the function QueryProThemeRequest of the file src/main/java/com/tduck/cloud/form/request/QueryProThemeRequest.java. The manipulation of the argument color leads to sql injection. The β¦
6.9
CVE-2025-0557 - Hyland Alfresco Community Edition URL s cross site scripting
A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the β¦
9.8
CVE-2024-13375 - Adifier System <= 3.1.7 - Unauthenticated Arbitrary Password Reset
The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the adifier_recover() function. Tβ¦
7.5
CVE-2024-13184 - The Ultimate WordPress Toolkit β WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Atβ¦
The The Ultimate WordPress Toolkit β WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing Sβ¦
6.4
CVE-2024-13392 - Rate Star Review Vote β AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Sβ¦
The Rate Star Review Vote β AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied aβ¦
6.4
CVE-2024-13433 - Utilities for MTG <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Utilities for MTG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mtglink' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated aβ¦
6.4
CVE-2024-13393 - Video Share VOD β Turnkey Video Site Builder Script <= 2.6.31 - Authenticated (Contributor+) Storedβ¦
The Video Share VOD β Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in all versions up to, and including, 2.6.31 due to insufficient input sanitization and output escaping on user supplied attribuβ¦
6.4
CVE-2025-0369 - Jet Engine <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parametβ¦
The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βlist_tagβ parameter in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and β¦
6.4
CVE-2024-12696 - Picture Gallery β Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) β¦
The Picture Gallery β Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videowhisper_picture_upload_guest shortcode in all versions up to, and including, 1.5.22 due to insufficient input sanitization and output escaping on useβ¦
6.4
CVE-2024-13385 - JSM Screenshot Machine Shortcode <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ssm' shortcode in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authβ¦