6.9

CVSS4.0

CVE-2025-4917 - PHPGurukul Auto Taxi Stand Management System new-autoortaxi-entry-form.php sql injection

A vulnerability classified as critical has been found in PHPGurukul Auto Taxi Stand Management System 1.0. Affected is an unknown function of the file /admin/new-autoortaxi-entry-form.php. The manipulation of the argument drivername leads to sql injection. It is possible to launch the attack remote…

πŸ“… Published: May 19, 2025, 7:31 a.m. πŸ”„ Last Modified: May 19, 2025, 5:38 p.m.

9.3

CVSS4.0

CVE-2025-46801 -

Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disab…

πŸ“… Published: May 19, 2025, 7:14 a.m. πŸ”„ Last Modified: Nov. 3, 2025, 6:16 p.m.

6.9

CVSS4.0

CVE-2025-4916 - PHPGurukul Auto Taxi Stand Management System admin-profile.php sql injection

A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. …

πŸ“… Published: May 19, 2025, 7 a.m. πŸ”„ Last Modified: May 19, 2025, 5:37 p.m.

6.9

CVSS4.0

CVE-2025-4915 - PHPGurukul Auto Taxi Stand Management System auto-taxi-entry-detail.php sql injection

A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/auto-taxi-entry-detail.php. The manipulation of the argument price leads to sql injection. The attack can be initiated remotely…

πŸ“… Published: May 19, 2025, 6:31 a.m. πŸ”„ Last Modified: May 27, 2025, 8:28 p.m.

6.9

CVSS4.0

CVE-2025-4914 - PHPGurukul Auto Taxi Stand Management System forgot-password.php sql injection

A vulnerability was found in PHPGurukul Auto Taxi Stand Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The …

πŸ“… Published: May 19, 2025, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 5:37 p.m.

4.8

CVSS3.1

CVE-2025-2561 - Ninja Forms < 3.10.1 - Admin+ Stored XSS

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: May 19, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.

4.8

CVSS3.1

CVE-2025-2560 - Ninja Forms < 3.10.1 - Admin+ Stored XSS

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: May 19, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.

4.8

CVSS3.1

CVE-2025-2524 - Ninja Forms < 3.10.1 - Admin+ Stored XSS

The Ninja Forms WordPress plugin before 3.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: May 19, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.

5.4

CVSS3.1

CVE-2025-1627 - Qi Blocks < 1.4 - Contributor+ Stored XSS via ToC Block

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: May 19, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.

5.4

CVSS3.1

CVE-2025-1626 - Qi Blocks < 1.4 - Contributor+ Stored XSS vi Countdown Block

The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: May 19, 2025, 6 a.m. πŸ”„ Last Modified: Jan. 9, 2026, 9:16 p.m.
Total resulsts: 342218
Page 4650 of 34,222
Β« previous page Β» next page
Filters