Latest CVE Feed
-
8.8
HIGHCVE-2025-45956
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter... Read more
Affected Products : computer_laboratory_management_system- Published: Apr. 29, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3817
A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=delete_stock. The manipulation of the argument ID leads to sql i... Read more
Affected Products : online_eyewear_shop- Published: Apr. 19, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-3765
A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument Avatar leads to ... Read more
- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-3764
A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This vulnerability affects unknown code of the file /edit-product.php. The manipulation of the argument Avatar leads to unrestricted uploa... Read more
- Published: Apr. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-4314
A vulnerability has been found in SourceCodester Advanced Web Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument txtLogin leads to sql injection. ... Read more
Affected Products : advanced_web_store- Published: May. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4313
A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an unknown function of the file /admin/admin_addnew_product.php. The manipulation of the argument txtProdId leads to sql injection. It is po... Read more
Affected Products : advanced_web_store- Published: May. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4312
A vulnerability, which was classified as critical, has been found in SourceCodester Advanced Web Store 1.0. This issue affects some unknown processing of the file /productdetail.php. The manipulation of the argument prodid leads to sql injection. The atta... Read more
Affected Products : advanced_web_store- Published: May. 06, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-4283
A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injecti... Read more
- Published: May. 05, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-4282
A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The ... Read more
- Published: May. 05, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2025-4470
A vulnerability classified as problematic was found in SourceCodester Online Student Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-student.php. The manipulation of the argument Fullname leads to cr... Read more
Affected Products : online_student_clearance_system- Published: May. 09, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-4468
A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument userImage leads to unrestricted upload... Read more
Affected Products : online_student_clearance_system- Published: May. 09, 2025
- Modified: May. 14, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2024-13493
The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disa... Read more
Affected Products : sensly_online_presence- Published: Feb. 14, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-7052
The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : forminator_forms- Published: Feb. 14, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-13208
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more
Affected Products : wp_google_map- Published: Feb. 15, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-13306
The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_... Read more
Affected Products : wp_google_map- Published: Feb. 15, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13603
The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks via malicious form submissions.... Read more
Affected Products : wise_forms- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.7
MEDIUMCVE-2024-13608
The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks... Read more
Affected Products : track_logins- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-13625
The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : tube_video_ads_lite- Published: Feb. 17, 2025
- Modified: May. 14, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-10939
The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : image_widget- Published: Dec. 13, 2024
- Modified: May. 14, 2025
-
5.3
MEDIUMCVE-2024-5333
The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events.... Read more
Affected Products : the_events_calendar- Published: Dec. 16, 2024
- Modified: May. 14, 2025