5.5

CVSS3.1

CVE-2025-48910 -

Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.

📅 Published: June 6, 2025, 6:47 a.m. 🔄 Last Modified: July 11, 2025, 2:26 p.m.

7.1

CVSS3.1

CVE-2025-48909 -

Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

📅 Published: June 6, 2025, 6:45 a.m. 🔄 Last Modified: July 11, 2025, 2:25 p.m.

6.4

CVSS3.1

CVE-2025-5686 - Paged Gallery <= 0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Paged Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:34 p.m.

6.5

CVSS3.1

CVE-2025-5563 - WP-Addpub <= 1.2.8 - Authenticated (Contributor+) SQL Injection

The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, and including, 1.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authentic…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

9.8

CVSS3.1

CVE-2025-5486 - WP Email Debug 1.0 - 1.1.0 - Missing Authorization to Unauthenticated Privilege Escalation via Pass…

The WP Email Debug plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the WPMDBUG_handle_settings() function in versions 1.0 to 1.1.0. This makes it possible for unauthenticated attackers to enable debugging and send all emails to an attacker controlled …

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: June 6, 2025, 4:08 p.m.

6.4

CVSS3.1

CVE-2025-5541 - Runners Log <= 3.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Runners Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'runnerslog' shortcode in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:23 p.m.

6.4

CVSS3.1

CVE-2025-5565 - Hide It <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Hide It plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hideit' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, w…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

5.4

CVSS3.1

CVE-2025-2935 - Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms <= 2024.7 - Cross-Site Request Forge…

The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This m…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 7:24 p.m.

6.4

CVSS3.1

CVE-2025-5538 - BNS Featured Category <= 2.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The BNS Featured Category plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bnsfc' shortcode in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

4.9

CVSS3.1

CVE-2025-4964 - WP Online Users Stats <= 1.0.0 - Authenticated (Editor+) SQL Injection via table_name Parameter

The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parameter in all versions up to, and including, 1.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes i…

📅 Published: June 6, 2025, 6:42 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.
Total resulsts: 344676
Page 4705 of 34,468
« previous page » next page
Filters