8.8

CVSS3.1

CVE-2023-2921 - Short URL <= 1.6.8 - Subscriber+ SQLi

The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.

πŸ“… Published: June 6, 2025, 6 a.m. πŸ”„ Last Modified: June 10, 2025, 7:31 p.m.

4.8

CVSS4.0

CVE-2025-5725 - SourceCodester Student Result Management System Grading System Page grading-system cross site scrip…

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/academic/grading-system of the component Grading System Page. The manipulation of the argument Remark…

πŸ“… Published: June 6, 2025, 5:31 a.m. πŸ”„ Last Modified: June 10, 2025, 2:58 p.m.

4.8

CVSS4.0

CVE-2025-5724 - SourceCodester Student Result Management System Subjects Page subjects cross site scripting

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /script/academic/subjects of the component Subjects Page. The manipulation of the argument Subject leads to cross site scripting. It i…

πŸ“… Published: June 6, 2025, 5:31 a.m. πŸ”„ Last Modified: June 10, 2025, 2:58 p.m.

6.4

CVSS3.1

CVE-2025-1777 - BM Content Builder <= 3.16.2.1 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-…

The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'ux_cb_page_options_save' function in all versions up to, and including, 3.16.2.1. This makes it possible for authenticated attackers, with subscriber-level access and…

πŸ“… Published: June 6, 2025, 5:22 a.m. πŸ”„ Last Modified: April 20, 2026, 10:45 p.m.

4.3

CVSS3.1

CVE-2025-1778 - Art Theme <= 3.12.2.3 - Missing Authorization to Authenticated (Subscriber+) Theme Option Delete

The Art Theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'arttheme_theme_option_restore' AJAX function in all versions up to, and including, 3.12.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to dele…

πŸ“… Published: June 6, 2025, 5:22 a.m. πŸ”„ Last Modified: April 21, 2026, 8:30 p.m.

4.8

CVSS4.0

CVE-2025-5723 - SourceCodester Student Result Management System Classes Page classes cross site scripting

A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/academic/classes of the component Classes Page. The manipulation of the argument Class Name leads to cross site scripting. T…

πŸ“… Published: June 6, 2025, 5 a.m. πŸ”„ Last Modified: June 10, 2025, 2:59 p.m.

4.8

CVSS4.0

CVE-2025-5722 - SourceCodester Student Result Management System Add Academic Term terms cross site scripting

A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /script/academic/terms of the component Add Academic Term. The manipulation of the argument Academic Term leads to cross site scri…

πŸ“… Published: June 6, 2025, 4:31 a.m. πŸ”„ Last Modified: June 10, 2025, 2:59 p.m.

5.1

CVSS4.0

CVE-2025-36513 -

Cross-site request forgery vulnerability exists in surveillance cameras provided by i-PRO Co., Ltd.. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

πŸ“… Published: June 6, 2025, 4:29 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-5721 - SourceCodester Student Result Management System Profile Setting Page update_profile cross site scri…

A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation leads to cross site scripting. It is possible…

πŸ“… Published: June 6, 2025, 4 a.m. πŸ”„ Last Modified: June 10, 2025, 3:47 p.m.

5.3

CVSS3.1

CVE-2025-5733 - Modern Events Calendar <= 7.21.9 - Information Exposure

The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the …

πŸ“… Published: June 6, 2025, 3:41 a.m. πŸ”„ Last Modified: April 22, 2026, 7:45 a.m.
Total resulsts: 347008
Page 4941 of 34,701
Β« previous page Β» next page
Filters