5.3

CVSS3.1

CVE-2025-62085 - WordPress BERTHA AI plugin <= 1.13 - Broken Access Control vulnerability

Missing Authorization vulnerability in Bertha AI &#8211; Andrew Palmer BERTHA AI bertha-ai-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BERTHA AI: from n/a through <= 1.13.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

6.5

CVSS3.1

CVE-2025-62082 - WordPress Generic Elements plugin <= 1.2.9 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nasir Uddin Generic Elements generic-elements-for-elementor allows Stored XSS.This issue affects Generic Elements: from n/a through <= 1.2.9.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 3:18 p.m.

4.3

CVSS3.1

CVE-2025-59132 - WordPress Duplicate Content Cure plugin <= 1.0 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Badi Jones Duplicate Content Cure duplicate-content-cure allows Cross Site Request Forgery.This issue affects Duplicate Content Cure: from n/a through <= 1.0.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:08 p.m.

7.1

CVSS3.1

CVE-2025-49351 - WordPress Create Posts & Terms plugin <= 1.3.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts &amp; Terms create-posts-terms allows Stored XSS.This issue affects Create Posts &amp; Terms: from n/a through <= 1.3.1.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:07 p.m.

4.3

CVSS3.1

CVE-2025-49350 - WordPress Actionwear products sync plugin <= 2.3.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in marcoingraiti Actionwear products sync actionwear-products-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Actionwear products sync: from n/a through <= 2.3.3.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:07 p.m.

5.3

CVSS3.1

CVE-2025-49348 - WordPress Hype plugin <= 1.0.5 - Broken Access Control vulnerability

Missing Authorization vulnerability in Hype Hype pico allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hype: from n/a through <= 1.0.5.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:07 p.m.

7.1

CVSS3.1

CVE-2025-49347 - WordPress WP sIFR plugin <= 0.6.8.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sIFR: from n/a through <= 0.6.8.1.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:07 p.m.

7.1

CVSS3.1

CVE-2025-49341 - WordPress PDF Creator Lite plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This issue affects PDF Creator Lite: from n/a through <= 1.2.

๐Ÿ“… Published: Dec. 9, 2025, 2:52 p.m. ๐Ÿ”„ Last Modified: April 1, 2026, 2:07 p.m.

8.6

CVSS4.0

CVE-2025-10655 - Frappe Helpdesk 1.14.0 โ€” SQL Injection in dashboard get_dashboard_data

SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.

๐Ÿ“… Published: Dec. 9, 2025, 2:49 p.m. ๐Ÿ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

9.8

CVSS3.1

CVE-2025-12504 - SQLi in Talent Software's UNIS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection.This issue affects UNIS: before 42321.

๐Ÿ“… Published: Dec. 9, 2025, 2:26 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2026, 2:33 p.m.
Total resulsts: 342297
Page 2040 of 34,230
ยซ previous page ยป next page
Filters