5.3

CVSS3.1

CVE-2024-13498 - NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitiv…

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes …

📅 Published: March 12, 2025, 5:22 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-24912 - hostapd: RADIUS Packet Processing Flaw in hostapd

hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and the RADIUS server may inject crafted RADIUS packets and force RADIUS authentications to fail.

📅 Published: March 12, 2025, 4:43 a.m. 🔄 Last Modified: Oct. 24, 2025, 6:40 p.m.

6.1

CVSS3.1

CVE-2025-2077 - Simple Amazon Affiliate <= 1.0.9 - Reflected Cross-Site Scripting

The Simple Amazon Affiliate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'msg' parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w…

📅 Published: March 12, 2025, 3:21 a.m. 🔄 Last Modified: April 22, 2026, 2 a.m.

4.4

CVSS3.1

CVE-2025-2078 - BlogBuzzTime-for-wp <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions…

📅 Published: March 12, 2025, 3:21 a.m. 🔄 Last Modified: April 22, 2026, 2 a.m.

5.3

CVSS3.1

CVE-2025-1508 - WP Crowdfunding <= 2.1.14 - Missing Authorization to Authenticated (Subscriber+) Post Content Downl…

The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_data action in all versions up to, and including, 2.1.14. This makes it possible for authenticated attackers, with subscriber-level access and above, to download a…

📅 Published: March 12, 2025, 3:21 a.m. 🔄 Last Modified: April 22, 2026, 2 a.m.

4.4

CVSS3.1

CVE-2025-2076 - binlayerpress <= 1.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The binlayerpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a…

📅 Published: March 12, 2025, 3:21 a.m. 🔄 Last Modified: April 21, 2026, 10 p.m.

4.4

CVSS3.1

CVE-2025-2205 - GDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting

The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.6 due to insufficient input sanitization and output escaping. This makes it p…

📅 Published: March 12, 2025, 3:21 a.m. 🔄 Last Modified: April 21, 2026, 10:15 p.m.

4.8

CVSS4.0

CVE-2025-2220 - Odyssey CMS reCAPTCHA odyssey_contact_form.php key management

A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of the component reCAPTCHA Handler. The manipulation of the argument g-recaptcha-response leads to key mana…

📅 Published: March 12, 2025, 1 a.m. 🔄 Last Modified: March 25, 2025, 5:15 p.m.

6.9

CVSS4.0

CVE-2025-2219 - LoveCards LoveCardsV2 image unrestricted upload

A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unknown processing of the file /api/upload/image. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclos…

📅 Published: March 12, 2025, 12:31 a.m. 🔄 Last Modified: March 25, 2025, 5:19 p.m.

6.9

CVSS4.0

CVE-2025-2218 - LoveCards LoveCardsV2 Setting other access control

A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affects unknown code of the file /api/system/other of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The explo…

📅 Published: March 12, 2025, 12:31 a.m. 🔄 Last Modified: March 25, 2025, 5:21 p.m.
Total resulsts: 347398
Page 6182 of 34,740
« previous page » next page
Filters