7.1

CVSS3.1

CVE-2025-32300 - WordPress DZS Video Gallery plugin <= 12.25 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25.

πŸ“… Published: Jan. 7, 2026, 12:06 p.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

8.8

CVSS3.1

CVE-2025-31643 - WordPress WPCHURCH plugin <= 2.7.0 - Privilege Escalation Vulnerability

Incorrect Privilege Assignment vulnerability in Dasinfomedia WPCHURCH allows Privilege Escalation.This issue affects WPCHURCH: from n/a through 2.7.0.

πŸ“… Published: Jan. 7, 2026, 12:05 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:38 p.m.

8.1

CVSS3.1

CVE-2025-69080 - WordPress Gecko theme <= 1.9.8 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through 1.9.8.

πŸ“… Published: Jan. 7, 2026, 11:59 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

8.1

CVSS3.1

CVE-2025-69081 - WordPress Hope theme <= 3.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Group Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through 3.0.0.

πŸ“… Published: Jan. 7, 2026, 11:56 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

7.1

CVSS3.1

CVE-2025-69082 - WordPress Arlo theme <= 6.0.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through 6.0.3.

πŸ“… Published: Jan. 7, 2026, 11:54 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

4.3

CVSS3.1

CVE-2025-69333 - WordPress JetEngine plugin <= 3.8.1.1 - Broken Access Control vulnerability

Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.8.1.1.

πŸ“… Published: Jan. 7, 2026, 11:52 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

4.3

CVSS3.1

CVE-2025-69344 - WordPress Oneline Lite theme <= 6.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in ThemeHunk Oneline Lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through 6.6.

πŸ“… Published: Jan. 7, 2026, 11:51 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

9.1

CVSS3.1

CVE-2025-68637 - Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This…

πŸ“… Published: Jan. 7, 2026, 9:39 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

5.3

CVSS3.1

CVE-2025-13722 - Fluent Forms <= 6.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creatio…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.1.7. This is due to missing capability checks on the `fluentform_ai_create_form` AJAX action. This makes it …

πŸ“… Published: Jan. 7, 2026, 9:21 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.

4.4

CVSS3.1

CVE-2025-14057 - Multi-column Tag Map <= 17.0.39 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'm…

The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 17.0.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permis…

πŸ“… Published: Jan. 7, 2026, 9:21 a.m. πŸ”„ Last Modified: Jan. 8, 2026, 6:08 p.m.
Total resulsts: 327160
Page 69 of 32,716
Β« previous page Β» next page
Filters