7.1

CVSS3.1

CVE-2025-49347 - WordPress WP sIFR plugin <= 0.6.8.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sIFR: from n/a through <= 0.6.8.1.

πŸ“… Published: Dec. 9, 2025, 2:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:07 p.m.

7.1

CVSS3.1

CVE-2025-49341 - WordPress PDF Creator Lite plugin <= 1.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This issue affects PDF Creator Lite: from n/a through <= 1.2.

πŸ“… Published: Dec. 9, 2025, 2:52 p.m. πŸ”„ Last Modified: April 1, 2026, 2:07 p.m.

8.6

CVSS4.0

CVE-2025-10655 - Frappe Helpdesk 1.14.0 β€” SQL Injection in dashboard get_dashboard_data

SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.

πŸ“… Published: Dec. 9, 2025, 2:49 p.m. πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

9.8

CVSS3.1

CVE-2025-12504 - SQLi in Talent Software's UNIS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection.This issue affects UNIS: before 42321.

πŸ“… Published: Dec. 9, 2025, 2:26 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 2:33 p.m.

5.4

CVSS3.1

CVE-2025-6923 - Reflected XSS in Talent Software's UNIS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS.This issue affects UNIS: before 42957.

πŸ“… Published: Dec. 9, 2025, 2:19 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 1:15 p.m.

4.3

CVSS3.1

CVE-2025-67599 - WordPress WebToffee eCommerce Marketing Automation plugin <= 2.1.1 - Broken Access Control vulnerab…

Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1.

πŸ“… Published: Dec. 9, 2025, 2:14 p.m. πŸ”„ Last Modified: April 1, 2026, 2:11 p.m.

4.3

CVSS3.1

CVE-2025-67598 - WordPress SupportCandy plugin <= 3.4.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugins SupportCandy supportcandy allows Cross Site Request Forgery.This issue affects SupportCandy: from n/a through <= 3.4.1.

πŸ“… Published: Dec. 9, 2025, 2:14 p.m. πŸ”„ Last Modified: April 1, 2026, 2:11 p.m.

4.3

CVSS3.1

CVE-2025-67597 - WordPress Fluent Booking plugin <= 1.9.11 - Broken Access Control vulnerability

Missing Authorization vulnerability in Shahjahan Jewel Fluent Booking fluent-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Booking: from n/a through <= 1.9.11.

πŸ“… Published: Dec. 9, 2025, 2:14 p.m. πŸ”„ Last Modified: April 1, 2026, 2:11 p.m.

4.3

CVSS3.1

CVE-2025-67596 - WordPress Business Directory plugin <= 6.4.19 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Cross Site Request Forgery.This issue affects Business Directory: from n/a through <= 6.4.19.

πŸ“… Published: Dec. 9, 2025, 2:14 p.m. πŸ”„ Last Modified: April 1, 2026, 2:11 p.m.

4.3

CVSS3.1

CVE-2025-67595 - WordPress Quiz Maker plugin <= 6.7.0.82 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.

πŸ“… Published: Dec. 9, 2025, 2:14 p.m. πŸ”„ Last Modified: April 1, 2026, 2:11 p.m.
Total resulsts: 342311
Page 2042 of 34,232
Β« previous page Β» next page
Filters