6.6

CVSS4.0

CVE-2025-48490 - Laravel Rest Api has a Search Validation Bypass

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, an…

📅 Published: May 30, 2025, 5:27 a.m. 🔄 Last Modified: May 30, 2025, 4:31 p.m.

5.3

CVSS3.1

CVE-2025-4659 - Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.4…

The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web applicatio…

📅 Published: May 30, 2025, 5:23 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.4

CVSS3.1

CVE-2025-5259 - Minimal Share Buttons <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via align…

The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level ac…

📅 Published: May 30, 2025, 5:23 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

8.3

CVSS3.1

CVE-2025-48881 - Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthori…

Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12.0.0.RELEASE to 12.12.0.RELEASE, all objects for which an object-management configuration exists can be listed, viewed, edited, created or deleted by unauthorised users. If object…

📅 Published: May 30, 2025, 5:21 a.m. 🔄 Last Modified: June 4, 2025, 9:15 p.m.

4.6

CVSS4.0

CVE-2025-48484 - FreeScout Vulnerable to Stored XSS

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data in the conversation POST data body. This issue has been patched in versio…

📅 Published: May 30, 2025, 4:59 a.m. 🔄 Last Modified: June 4, 2025, 3:34 p.m.

6.3

CVSS4.0

CVE-2025-48483 - FreeScout Stored XSS leads to CSRF

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sanitization. An attacker can inject arbitrary HTML…

📅 Published: May 30, 2025, 4:58 a.m. 🔄 Last Modified: June 4, 2025, 3:35 p.m.

5.3

CVSS4.0

CVE-2025-48482 - FreeScout Has Business Logic Errors

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, the fill() method is called with all client-provi…

📅 Published: May 30, 2025, 4:35 a.m. 🔄 Last Modified: June 4, 2025, 3:35 p.m.

6.1

CVSS4.0

CVE-2025-48481 - FreeScout Has Business Logic Errors

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it being blocked or deleted, by leveraging the invitation link from…

📅 Published: May 30, 2025, 4:35 a.m. 🔄 Last Modified: June 4, 2025, 3:35 p.m.

7

CVSS4.0

CVE-2025-48480 - FreeScout Has Business Logic Errors

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar ../.htaccess during creation, and then delete the user's ava…

📅 Published: May 30, 2025, 4:34 a.m. 🔄 Last Modified: June 4, 2025, 3:35 p.m.

8.5

CVSS4.0

CVE-2025-48479 - FreeScout Has Business Logic Errors

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue has been patched in version 1.8.180.

📅 Published: May 30, 2025, 4:34 a.m. 🔄 Last Modified: June 4, 2025, 3:36 p.m.
Total resulsts: 343975
Page 4702 of 34,398
« previous page » next page
Filters