7.5

CVSS3.1

CVE-2025-15268 - Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist…

The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API action in all versions up to, and including, 2.14.46. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, midnight

4.4

CVSS3.1

CVE-2026-0681 - Extended Random Number Generator <= 1.1 - Authenticated (Administrator+) Stored Cross-Site Scriptin…

The Extended Random Number Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 15, 2026, 9:30 p.m.

7.5

CVSS3.1

CVE-2025-15285 - SEO Flow by LupsOnline <= 2.2.1 - Unauthenticated Arbitrary Post/Category Modification

The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the checkBlogAuthentication() and checkCategoryAuthentication() functions in all versions up to, and including, 2.2.1. These authorization functions only implement…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, midnight

5.3

CVSS3.1

CVE-2025-14461 - Xendit Payment <= 6.0.2 - Missing Authorization to Unauthenticated Arbitrary Order Status Update to…

The Xendit Payment plugin for WordPress is vulnerable to unauthorized order status manipulation in all versions up to, and including, 6.0.2. This is due to the plugin exposing a publicly accessible WooCommerce API callback endpoint (`wc_xendit_callback`) that processes payment callbacks without any…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 3:45 p.m.

6.5

CVSS3.1

CVE-2025-15260 - MyRewards – Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenti…

The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax' function. This makes it p…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 3:45 p.m.

5.3

CVSS3.1

CVE-2025-15482 - Chapa Payment Gateway Plugin for WooCommerce <= 1.0.3 - Unauthenticated Sensitive Information Expos…

The Chapa Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.3 via 'chapa_proceed' WooCommerce API endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including th…

📅 Published: Feb. 4, 2026, 8:25 a.m. 🔄 Last Modified: April 22, 2026, 3:45 p.m.

8.8

CVSS3.1

CVE-2026-1819 - Stored XSS in Karel Electronics' ViPort

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Karel Electronics Industry and Trade Inc. ViPort allows Stored XSS.This issue affects ViPort: through 23012026.

📅 Published: Feb. 4, 2026, 7:52 a.m. 🔄 Last Modified: April 18, 2026, midnight

4.8

CVSS4.0

CVE-2026-24447 - CSV Export Malformed Data Leading to Embedded Code Execution

If a malformed data is input to the affected product, a CSV file downloaded from the affected product may contain such malformed data. When a victim user download and open such a CSV file, the embedded code may be executed in the user's environment. Note that Movable Type 7 series and 8.4 series, w…

📅 Published: Feb. 4, 2026, 7:04 a.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

5.1

CVSS4.0

CVE-2026-23704 - Unrestricted File Upload Enables Client‑Side Script Execution in Movable Type

A non-administrative user can upload malicious files. When an administrator or the product accesses that file, an arbitrary script may be executed on the administrator's browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerability as well.

📅 Published: Feb. 4, 2026, 7:03 a.m. 🔄 Last Modified: April 18, 2026, 2:15 p.m.

4.8

CVSS4.0

CVE-2026-22875 - Stored Cross‑Site Scripting in Export Sites

Movable Type contains a stored cross-site scripting vulnerability in Export Sites. If crafted input is stored by an attacker, arbitrary script may be executed on a logged-in user's web browser. Note that Movable Type 7 series and 8.4 series, which are End-of-Life (EOL), are affected by the vulnerab…

📅 Published: Feb. 4, 2026, 7:03 a.m. 🔄 Last Modified: April 18, 2026, 2:15 p.m.
Total resulsts: 349182
Page 1807 of 34,919
« previous page » next page
Filters