5.3

CVSS4.0

CVE-2025-0204 - code-projects Online Shoe Store details.php sql injection

A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to t…

📅 Published: Jan. 4, 2025, 7:31 a.m. 🔄 Last Modified: Jan. 22, 2025, 3:42 p.m.

8.8

CVSS3.1

CVE-2024-10932 - Backup Migration <= 1.4.6 - Unauthenticated PHP Object Injection via 'recursive_unserialize_replace'

The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the 'recursive_unserialize_replace' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additi…

📅 Published: Jan. 4, 2025, 7:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-12545 - Scratch & Win – Giveaways and Contests <= 2.7.1 - Cross-Site Request Forgery via reset_installation…

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.1. This is due to missing nonce validation on the reset_installation() functio…

📅 Published: Jan. 4, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-11974 - Media Library Assistant <= 3.23 - Reflected Cross-Site Scripting via smc_settings_tab, unattachfixi…

The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’ parameters in all versions up to, and including, 3.23 due to insufficient input sanitization and output escaping. This makes it …

📅 Published: Jan. 4, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.

6.1

CVSS3.1

CVE-2024-12701 - WP Smart Import : Import any XML File to WordPress <= 1.1.2 - Reflected Cross-Site Scripting

The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at…

📅 Published: Jan. 4, 2025, 7:24 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12047 - WP Compress – Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting …

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. This makes it possible for unau…

📅 Published: Jan. 4, 2025, 7:24 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

5.3

CVSS4.0

CVE-2025-0203 - code-projects Student Management System DbFunction.php showSubject1 sql injection

A vulnerability was found in code-projects Student Management System 1.0. It has been declared as critical. This vulnerability affects the function showSubject1 of the file /config/DbFunction.php. The manipulation of the argument sid leads to sql injection. The attack can be initiated remotely. The…

📅 Published: Jan. 4, 2025, 7 a.m. 🔄 Last Modified: Jan. 22, 2025, 3:47 p.m.

5.1

CVSS4.0

CVE-2025-0202 - TCS BaNCS REPORTS_SHOW_FILE.jsp file inclusion

A vulnerability was found in TCS BaNCS 10. It has been classified as problematic. This affects an unknown part of the file /REPORTS/REPORTS_SHOW_FILE.jsp. The manipulation of the argument FilePath leads to file inclusion. The real existence of this vulnerability is still doubted at the moment.

📅 Published: Jan. 4, 2025, 5 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-0201 - code-projects Point of Sales and Inventory Management System update_account.php sql injection

A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user/update_account.php. The manipulation of the argument username leads to sql injection. The attack may be la…

📅 Published: Jan. 4, 2025, 4 a.m. 🔄 Last Modified: Feb. 25, 2025, 10:44 p.m.

5.3

CVSS4.0

CVE-2025-0200 - code-projects Point of Sales and Inventory Management System search_num.php sql injection

A vulnerability has been found in code-projects Point of Sales and Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /user/search_num.php. The manipulation of the argument search leads to sql injection. The attack can …

📅 Published: Jan. 4, 2025, 3 a.m. 🔄 Last Modified: Feb. 25, 2025, 10:44 p.m.
Total resulsts: 345001
Page 6868 of 34,501
« previous page » next page
Filters