Latest CVE Feed
-
5.4
MEDIUMCVE-2024-11831
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This c... Read more
Affected Products : enterprise_linux- Published: Feb. 10, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-2892
The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post Meta Description and Canonical URL parameters in all versions up to, and including, 4.8.1.1 du... Read more
Affected Products : all_in_one_seo- Published: May. 19, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.3
MEDIUMCVE-2025-4208
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the get_table_records function. This is due to the unsanitized use of user-sup... Read more
Affected Products : nex-forms- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Misconfiguration
-
6.4
MEDIUMCVE-2025-3862
Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta... Read more
Affected Products : contest_gallery- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3468
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient input sanit... Read more
Affected Products : nex-forms- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-2806
The tagDiv Composer plugin for WordPress, used by the Newspaper theme, is vulnerable to Reflected Cross-Site Scripting via the ‘data’ parameter in all versions up to, and including, 5.3 due to insufficient input sanitization and output escaping. This make... Read more
- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-4127
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it poss... Read more
Affected Products : wp_seo_structured_data_schema- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3419
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 4.0.26 via the proxy_image() function. This makes it possible for unauthenticated attacker... Read more
Affected Products : eventin- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2024-13793
The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.8.11. This is due to the software allowing users to execute an action that does not properl... Read more
Affected Products : wolmart- Published: May. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2025-4204
The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e... Read more
Affected Products : ultimate_wordpress_auction_plugin- Published: May. 02, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2025-3077
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button shortcode and Custom CSS field in all versions up to, and including, 28.0.3 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products : betheme- Published: Apr. 16, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-3276
The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Carousel block in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping. This makes it... Read more
Affected Products : skt_blocks- Published: Apr. 12, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-3431
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read t... Read more
Affected Products : zoomsounds- Published: Apr. 08, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-2789
The MultiVendorX – Empower Your WooCommerce Store with a Dynamic Multivendor Marketplace – Build the Next Amazon, eBay, Etsy plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_table_rate_shippin... Read more
Affected Products : multivendorx- Published: Apr. 05, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2025-0839
The ZoomSounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 6.91 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe... Read more
Affected Products : zoomsounds- Published: Apr. 05, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-13776
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versi... Read more
Affected Products : zoomsounds- Published: Apr. 05, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2022-23088
The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may ove... Read more
Affected Products : freebsd- Published: Feb. 15, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22922
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php... Read more
Affected Products : visitor_management_system_in_php- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025
-
8.8
HIGHCVE-2024-22903
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.... Read more
Affected Products : vinchin_backup_and_recovery- Published: Feb. 02, 2024
- Modified: Jun. 04, 2025
-
9.8
CRITICALCVE-2024-22729
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.... Read more
- Published: Jan. 25, 2024
- Modified: Jun. 04, 2025