Latest CVE Feed
-
8.5
HIGHCVE-2025-31926
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player allows SQL Injection. This issue affects Sticky Radio Player: from n/a through 3.4.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
4.3
MEDIUMCVE-2025-32180
Missing Authorization vulnerability in QuanticaLabs CSS3 Tooltips for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CSS3 Tooltips for WordPress: from n/a through 1.8.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-32290
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player allows SQL Injection. This issue affects Sticky HTML5 Music Player: from n/a through 3.1.6.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-32296
Missing Authorization vulnerability in quantumcloud Simple Link Directory Pro allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple Link Directory Pro: from n/a through 14.7.3.... Read more
Affected Products : simple_link_directory- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2025-32301
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown Pro WP Plugin allows SQL Injection. This issue affects CountDown Pro WP Plugin: from n/a through 2.7.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
8.5
HIGHCVE-2025-32306
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio Player Shoutcast & Icecast WordPress Plugin allows Blind SQL Injection. This issue affects Radio Player Shoutcast & Icecast WordPress ... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-39491
Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through revision.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-39492
Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2 through revision.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2025-39537
Authorization Bypass Through User-Controlled Key vulnerability in Chimpstudio WP JobHunt allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP JobHunt: from n/a through 7.1.... Read more
Affected Products : jobcareer- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-40906
BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Per... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Supply Chain
-
4.3
MEDIUMCVE-2025-48115
Cross-Site Request Forgery (CSRF) vulnerability in Javier Revilla ValidateCertify allows Cross Site Request Forgery. This issue affects ValidateCertify: from n/a through 1.6.2.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.1
HIGHCVE-2025-48114
Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger allows Stored XSS. This issue affects ShayanWeb Admin FontChanger: from n/a through 1.8.1.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.5
MEDIUMCVE-2025-48113
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Broadstreet Broadstreet allows Stored XSS. This issue affects Broadstreet: from n/a through 1.51.8.... Read more
Affected Products : broadstreet- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-48112
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages allows Reflected XSS. This issue affects Dot html,php,xml etc pages: from n/a through 1.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-48080
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Stored XSS. This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.7.0.2.... Read more
Affected Products : uncanny_toolkit_for_learndash- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-47693
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in roninwp FAT Services Booking allows PHP Local File Inclusion. This issue affects FAT Services Booking: from n/a through 5.5.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Path Traversal
-
7.6
HIGHCVE-2025-47567
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video Player & FullScreen Video Background allows Blind SQL Injection. This issue affects Video Player & FullScreen Video Background: from n... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
5.3
MEDIUMCVE-2025-47562
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG allows Code Injection. This issue affects MapSVG: from n/a through 8.5.34.... Read more
Affected Products : mapsvg- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2025-47557
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RomanCode MapSVG allows Stored XSS. This issue affects MapSVG: from n/a through 8.5.31.... Read more
Affected Products : mapsvg- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-47534
Missing Authorization vulnerability in ValvePress Wordpress Auto Spinner allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Wordpress Auto Spinner: from n/a through 3.25.0.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Authorization